CVE-2026-5666 affects code-projects Online FIR System version 1.0 and involves insecure storage of sensitive information within the SQL Database Backup File Handler component, specifically in the /complaints.sql file. This vulnerability allows sensitive data to be stored in an unencrypted or otherwise inadequately protected manner that could be exposed to unauthorized access. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium severity) with a network attack vector, low complexity, and no authentication requirements, indicating it can be exploited remotely by unauthenticated threat actors. The impact is limited to confidentiality loss with no integrity or availability consequences, making it a data exposure risk rather than a critical system compromise. The exploit has been publicly disclosed and is available for use; however, it currently shows no active exploitation in the wild and has not been added to the CISA Known Exploited Vulnerabilities catalog. The EPSS score of 0.00041 indicates a very low probability of exploitation in the next 30 days relative to other known vulnerabilities, and the vulnerability maintains an inactive status on vulnerability tracking platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Code-Projects | Online FIR System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.