Executive brief
code-projects Simple Inventory System is a free open-source inventory management application. A flaw in the Database Backup File Handler allows the sensitive inventorymanagement.sql file to be accessed remotely without proper authentication, exposing database contents including potentially sensitive business data, user credentials, and customer information.
Technical details
This vulnerability is an information disclosure flaw in the Database Backup File Handler component of Simple Inventory System 1.0. The inventorymanagement.sql database backup file is exposed and accessible via network without authentication, likely due to misconfiguration or inadequate access controls on the backup file location. An attacker can remotely retrieve the complete SQL database dump, which may contain sensitive data such as user credentials, business records, and transaction history. The exploit is publicly available and requires no special privileges or user interaction to execute. Patch availability is not documented in the advisory.
Affected products
- code-projects Simple Inventory System 1.0
Timeline
- 2026-08-31: disclosed
- exploited: exploit published and may be used