Executive brief
SourceCodester Online Clothing Store is an e-commerce platform used to manage product catalogs and customer transactions. A SQL database backup file is publicly accessible without authentication, potentially exposing sensitive business data including customer information, product details, and administrative credentials to unauthorized access.
Technical details
The vulnerability is an information disclosure flaw affecting the SQL Database Backup component in SourceCodester Online Clothing Store 1.0, specifically the file /db/shopping.sql. The root cause is improper access controls or misconfiguration that leaves the database backup file publicly accessible over the network. An unauthenticated remote attacker can directly download the SQL backup file without authentication, gaining access to the entire database contents. The vulnerability allows extraction of sensitive data including customer records, payment information, and administrative credentials. No mitigation or patch information is currently available.
Affected products
- SourceCodester Online Clothing Store 1.0
Timeline
- 2026-08-15: disclosed
- 2026-08-15: advisory