Executive brief
Daily Expense Manager is a PHP-based expense tracking application. The application stores sensitive database backup files (.sql) in a web-accessible directory, allowing unauthenticated attackers to download the complete database containing all stored financial data and user information by directly requesting the backup file via HTTP.
Technical details
This vulnerability is a sensitive information disclosure issue caused by improper file placement in the web root. The vulnerable component is the Database Backup Handler, which stores SQL database dump files (exp_ak.sql) in the publicly accessible /Daily-Expense-Manager/ directory. An attacker can remotely request this file without authentication via HTTP GET requests and download the entire database backup, exposing user credentials, financial records, and other sensitive data. The root cause is a configuration/deployment error rather than a code flaw. The fix involves moving database files outside the web root, implementing proper access controls, and removing SQL files from the document root directory.
Affected products
- code-projects Daily Expense Manager 1.0
Timeline
- 2026-09-06: disclosed