Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by curiouscurrent - 27.08.2026
Last edited by cbay - 27.08.2026

FS#464 - Exposed always data user configuration details

Always data cloud mysql datasource configuration and alwaysdata database configuration details of an Alwaysdata user exposed in the github repository.

So i logged in to https://phpmyadmin.alwaysdata.com/ and i was able to access the database.

The github repo where the credentials are exposed : https://github.com/sushma23nov/CineBook/blob/33bdee3d8c94bbf51156d78466b5682343bac9b6/database.md?plain=1#L28

Fix : Ask them to store it in .env and to add it in .gitignore , and create a config file seperately for storing the configuration details.

Closed by  cbay
27.08.2026 14:53
Reason for closing:  Invalid
Admin
cbay commented on 27.08.2026 14:53

Hello,

Those are credentials from a customer, not ours.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing