CVE-2026-4532 Details
Description
A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. It is recommended to change the configuration settings.
A sensitive information disclosure vulnerability has been identified in Code-Projects Simple Food Ordering System versions through 1.0. The issue arises from an exposed database backup file, food.sql, which is accessible in a publicly reachable directory within the web root. This vulnerability allows remote users to download or view the entire SQL database dump without authentication, potentially leading to the exposure of sensitive information such as administrator credentials, user data, order records, and product information.
It is recommended to remove SQL backup files from the web root and store them in a secure location, such as /var/backups/. Access to .sql files should be restricted through server configuration, denying all requests to these file types. Additionally, database backups should be kept in secured storage environments with restricted access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code-projects.org/ | [email protected] | Product |
| https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Simple%20Food%20Ordering%20System%20Information%20Disclosure%20%20.md | [email protected] | ExploitMitigationThird Party Advisory |
| https://vuldb.com/?ctiid.352320 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.352320 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.774338 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-425 | Direct Request ('Forced Browsing') | [email protected] |
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| carmelo simple food order system | 1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | Initial Analysis | [email protected] |
| Mar 22, 2026 | New CVE Received | [email protected] |