CVE-2026-85517: code-projects Vehicle Management System SQL Database Backup File vehicle_management.sql information disclosure
A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehiclemanagement.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction according to the supplied vector. An attacker would need network access to a reachable affected deployment.
Is public exploitation a concern?
Yes. An exploit has been published and may be used, so exposed instances should be treated as having a practical disclosure risk.
How can I determine whether my deployment is affected?
Confirm whether the deployment is code-projects Vehicle Management System 1.0 and whether the /vehicle_management.sql database backup file is reachable through the application or web server. Exposure of that file indicates the affected component is present.