CVE-2026-4900 Details
Description
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. It is advisable to modify the configuration settings.
A sensitive information disclosure vulnerability has been identified in Code-Projects Online Food Ordering System version 1.0. The issue arises from an exposed database backup file, 'localhost.sql', which is stored in a publicly accessible directory without proper access restrictions. This file can be accessed remotely, allowing unauthorized users to download the database dump containing sensitive information such as user credentials, administrative accounts, and application data.
It is recommended to remove SQL backup files from the web root and store them in secure locations, such as internal systems not accessible via HTTP. Access to backup files should be restricted to administrators only.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 26, 2026CISA-ADP
Assessed Mar 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code-projects.org/ | [email protected] | Vendor |
| https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Online%20Food%20Ordering%20System%20in%20PHP%201.0%20%E2%80%93%20Sensitive%20Information%20Disclosure.md | [email protected] | ExploitRemedyTechnical Description |
| https://vuldb.com/?ctiid.353642 | [email protected] | Content Wall |
| https://vuldb.com/?id.353642 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/?submit.776980 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-425 | Direct Request ('Forced Browsing') | [email protected] |
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| code-projects Online Food Ordering System | 1.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | New CVE Received | [email protected] |
Volerion