Sceawere

Vulnerability Detail

CVE-2026-85517UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Vehicle Management System Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
5h ago
Vendor
code-projects
Product
Vehicle Management System
Attack Type
Information Disclosure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-04T14:17:22.633Z",
  "pubdate": "2026-09-04T14:17:22.633Z",
  "executiveSummary": "A critical information disclosure vulnerability exists in the SQL Database Backup File Handler component of Vehicle Management System 1.0.\nThe vulnerability originates from the /vehicle_management.sql file, allowing unauthorized remote access to sensitive database content.\nSuccessful exploitation permits a remote attacker to gain access to proprietary system information or potentially sensitive data stored within the database backup structure.\nGiven that proof-of-concept exploit code has been publicly disclosed, the risk profile is elevated due to the ease of weaponization by unauthorized actors.\nThis flaw represents a significant security risk, as it bypasses standard access controls to expose the underlying system data, necessitating immediate defensive measures to secure the database backup infrastructure.",
  "technicalDetails": "The vulnerability is situated within the SQL Database Backup File Handler of Vehicle Management System 1.0, specifically impacting the /vehicle_management.sql file.\nThe root cause of this flaw is the improper exposure of database backup files, which are often intended for administrative use, but are rendered accessible via a web-accessible directory or improperly secured function.\nThe attack flow involves an unauthenticated remote actor issuing a direct HTTP request to the URI corresponding to the /vehicle_management.sql file on the web server.\nBecause the component fails to implement adequate access control mechanisms or authentication checks for the backup file handler, the server responds with the contents of the SQL script.\nThe file contents typically contain database schema definitions, configuration strings, and potentially raw data entries stored within the system. By retrieving this file, the attacker obtains a comprehensive map of the database architecture, table structures, and potentially sensitive information such as credentials or user metadata stored in plain text or easily decodable formats.\nThis vulnerability is classified as an information disclosure issue. The attack does not necessarily require advanced administrative privileges, as the lack of an authentication wrapper around the file handler makes it accessible to any external entity with network connectivity to the host.\nThe post-exploitation impact includes unauthorized data harvesting, which serves as a precursor to more sophisticated attacks, such as SQL injection, credential stuffing, or targeted identity theft, depending on the information contained within the exposed database dump.\nThe availability of public exploit documentation suggests that the attack vector is well-understood and can be easily scripted, increasing the likelihood of automated exploitation by botnets or malicious actors scanning for misconfigured web applications."
}
CVE-2026-85517: Vehicle Management System Information Disclosure (MEDIUM Severity, CVSS: 5.3) - Sceawere