CVE-2026-5847 Details
Description
A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file /db/moviedb.sql of the component SQL Database Backup File Handler. Such manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
A sensitive information disclosure vulnerability has been identified in Code-Projects Movie Ticketing System version 1.0. The issue arises from an exposed SQL database backup file, 'moviedb.sql', which is stored in a publicly accessible directory within the web root. The web server does not restrict access to .sql files, allowing remote attackers to download the database dump without authentication. This SQL dump contains the full database structure and application data, including sensitive information such as user accounts, booking details, and administrative credentials.
It is recommended to remove database backup files from the web root and store them in secure locations that are not publicly accessible. Additionally, web servers should be configured to deny access to .sql files.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 9, 2026CISA-ADP
Assessed Apr 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code-projects.org/ | [email protected] | Vendor |
| https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Sensitive%20Information%20Disclosure%20in%20Movie%20Ticketing%20System%20PHP%20Exposed%20Database%20Backup.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/submit/790337 | [email protected] | Technical Description |
| https://vuldb.com/vuln/356373 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/356373/cti | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Code-Projects Movie Ticketing System | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 9, 2026 | New CVE Received | [email protected] |
Volerion