A flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file inventorymanagement.sql of the component Database Backup File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been published and may be used.
PUBLISHED5.2ApplicationCWE-200CWE-284x_freeware
code-projects Simple Inventory System Database Backup File inventorymanagement.sql information disclosure
Problem type
Affected products
code-projects
Simple Inventory System
1.0 - AFFECTED
References
VDB-397124 | code-projects Simple Inventory System Database Backup File inventorymanagement.sql information disclosure
https://vuldb.com/vuln/397124
VDB-397124 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/397124/cti
CVE-2026-82624 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-82624
Submit #893401 | code-projects Simple Inventory System In PHP With Source Code 1.0 Information Disclosure
https://vuldb.com/submit/893401
github.com
https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Sensitive%20Information%20Disclosure%20in%20Simple%20Inventory%20System%20PHP%20Exposed%20Database%20Backup.md
code-projects.org
https://code-projects.org/
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-82624Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-82624",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-08-31T06:30:09.424Z",
"dateReserved": "2026-08-30T08:12:13.070Z",
"datePublished": "2026-08-31T06:30:09.424Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-08-31T06:30:09.424Z"
},
"title": "code-projects Simple Inventory System Database Backup File inventorymanagement.sql information disclosure",
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file inventorymanagement.sql of the component Database Backup File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been published and may be used."
}
],
"affected": [
{
"vendor": "code-projects",
"product": "Simple Inventory System",
"cpes": [
"cpe:2.3:a:code-projects:simple_inventory_system:*:*:*:*:*:*:*:*"
],
"modules": [
"Database Backup File Handler"
],
"versions": [
{
"version": "1.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Information Disclosure",
"cweId": "CWE-200",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Improper Access Controls",
"cweId": "CWE-284",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/397124",
"name": "VDB-397124 | code-projects Simple Inventory System Database Backup File inventorymanagement.sql information disclosure",
"tags": [
"vdb-entry"
]
},
{
"url": "https://vuldb.com/vuln/397124/cti",
"name": "VDB-397124 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-82624",
"name": "CVE-2026-82624 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/893401",
"name": "Submit #893401 | code-projects Simple Inventory System In PHP With Source Code 1.0 Information Disclosure",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Sensitive%20Information%20Disclosure%20in%20Simple%20Inventory%20System%20PHP%20Exposed%20Database%20Backup.md",
"tags": [
"exploit"
]
},
{
"url": "https://code-projects.org/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"baseScore": 5
}
}
],
"timeline": [
{
"time": "2026-08-30T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-08-30T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-08-30T10:17:21.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "AhmadMarzook (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_freeware"
]
}
}
}