CVE-2026-103533
Deferred Deferred - Pending Action

Path Traversal in David-Crty Databasement

Vulnerability report for CVE-2026-103533, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been made public and could be used. Upgrading to version 1.7.2 will fix this issue. You should upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
david_crty databasement to 1.7.2 (exc)
david_crty databasement 1.7.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal flaw in the databasement application up to version 1.7.1. It allows attackers to manipulate the schema_name parameter during SQLite database restoration to write files to arbitrary locations, including the web root. This can lead to remote code execution by uploading a malicious SQLite file containing PHP code.

Detection Guidance

Check for unauthorized PHP files in web root directories, especially those with suspicious names or embedded code. Review logs for unusual restore operations or path traversal attempts in the databasement application. Inspect database server configurations for unvalidated schema_name parameters during restore operations.

Impact Analysis

An attacker with Member or Admin privileges could exploit this to upload a PHP webshell to your server's web root. This would allow them to execute arbitrary commands on your system, potentially leading to data theft, system compromise, or further network infiltration.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. A successful exploit may result in data breaches, unauthorized data access, or system modifications, all of which could lead to compliance violations and regulatory penalties.

Mitigation Strategies

Upgrade to version 1.7.2 or later immediately. Apply SafePath validation to schema_name parameters. Restrict restore target directories to prevent writes outside intended paths. Disable PHP execution in writable directories. Review and remove any unauthorized PHP files in web roots.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103533. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart