CVE-2026-5650 Details
Description
A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
A sensitive information disclosure vulnerability has been identified in Code-Projects Online Application System for Admission version 1.0. The issue arises from an exposed SQL database backup file, 'oas.sql', which is stored in a publicly accessible directory within the web root. The web server does not restrict access to .sql files, allowing remote users to download the database dump without authentication. This vulnerability exposes the complete database structure and application data, including user records, credentials, and personal information, to unauthorized users.
It is recommended to remove SQL files from the web root and store database backups in secure locations not accessible via HTTP. Access to backup files should be limited to authorized administrators only.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 6, 2026CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code-projects.org/ | [email protected] | Vendor |
| https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Sensitive%20Information%20Disclosure%20in%20Online%20Application%20System%20for%20Admission%20PHP%20Exposed%20Database%20Backup.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/submit/786307 | [email protected] | Technical Description |
| https://vuldb.com/vuln/355438 | [email protected] | AdvisoryExploitTechnical Description |
| https://vuldb.com/vuln/355438/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-922 | Insecure Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| code-projects Online Application System for Admission | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | New CVE Received | [email protected] |
Volerion