What is CVE-2026-19903?
A vulnerability in SourceCodester Online Clothing Store 1.0 allows remote attackers to access the SQL database backup file directly (/db/shopping.sql). This exposes sensitive data due to improper access restrictions on the backup component. It is recommended to restrict public access to the file immediately.
Azərbaycanca: SourceCodester Online Clothing Store 1.0 platformasında SQL verilənlər bazası ehtiyat nüsxə komponentində qorunmayan fayl əlçatanlığı zəifliyi aşkarlanıb (/db/shopping.sql). Bu, uzaqdan hücum edən şəxsə ehtiyat nüsxə faylına birbaşa giriş imkanı yaradır. İstifadəçilərə bu fayla ictimai girişi dərhal məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which file in SourceCodester Online Clothing Store is affected by the direct access vulnerability?
The SQL database backup file /db/shopping.sql is affected by the unprotected file accessibility vulnerability.
What can a remote attacker achieve by exploiting this vulnerability?
A remote attacker can gain direct access to the backup file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.