High severity7.5NVD Advisory· Published Nov 14, 2025· Updated Jul 5, 2026
CVE-2025-63891
CVE-2025-63891
Description
Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to /obs/database/obs_db.sql.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)
- cpe:2.3:a:oretnom23:simple_online_book_store_system:1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/lucascdsm/CVEs/blob/main/CVE-2025-63891.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.