# CVE-2026-19903

## Summary

- **CVE ID:** CVE-2026-19903
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-552, CWE-425
- **Published:** Aug 15, 2026
- **Last Modified:** Aug 17, 2026

## Description

A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

## Affected Products

- SourceCodester — Online Clothing Store (1.0)

## References

- [CNA](https://vuldb.com/vuln/390096)
- [CNA](https://vuldb.com/vuln/390096/cti)
- [CNA](https://vuldb.com/cve/CVE-2026-19903)
- [CNA](https://vuldb.com/submit/870782)
- [CNA](https://medium.com/@hemantrajbhati5555/sensitive-information-disclosure-via-publicly-accessible-sql-backup-leading-to-administrative-50bac3a307aa)
- [CNA](https://www.sourcecodester.com/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.31%
- **EPSS Percentile:** 23.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._