CVE-2025-63891: Infoleak
Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to /obs/database/obsdb.sql.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63891?
CVE-2025-63891 is classified as a high severity vulnerability due to the potential for unauthorized database access.
How do I fix CVE-2025-63891?
To fix CVE-2025-63891, remove or secure access to the /obs/database/obs_db.sql file to prevent unauthorized HTTP GET requests.
Who is affected by CVE-2025-63891?
CVE-2025-63891 affects users of the SourceCodester Simple Online Book Store System that expose the backup database file.
Can CVE-2025-63891 lead to data breaches?
Yes, CVE-2025-63891 can lead to data breaches as it allows attackers to access sensitive database information.
What kind of data can be disclosed through CVE-2025-63891?
CVE-2025-63891 can disclose full database contents, including schema and credential hashes.