CVE-2026-85517 Details
Description
A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used.
A sensitive information disclosure vulnerability has been identified in Code-Projects Vehicle Management System version 1.0. The issue arises from an SQL database backup file, 'vehicle_management.sql', being exposed in a publicly accessible directory. This vulnerability allows unauthorized users to retrieve the SQL file via direct HTTP requests, potentially disclosing sensitive information such as database schemas, user account details, and other application data.
SQL database files should be removed from public directories after installation and stored in secure, access-controlled locations. Web servers can be configured to deny access to SQL files and similar extensions, adding an extra layer of protection.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code-projects.org/ | [email protected] | Not ApplicableVendor |
| https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Vehicle%20Management%20System%20in%20PHP%20%E2%80%93%20Sensitive%20Information%20Disclosure%20via%20Exposed%20Database%20File.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/cve/CVE-2026-85517 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/895113 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/398681 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/398681/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Code-Projects Vehicle Management System | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion