Unrated severityNVD Advisory· Published Nov 14, 2025· Updated Nov 16, 2025
CVE-2025-63891
CVE-2025-63891
Description
Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to /obs/database/obs_db.sql.
Affected products
2- SourceCodester/Simple Online Book Store Systemdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.