Description
A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown function of the file /util/VehicleDetailsFunction.php. The manipulation of the argument VEHICLE_ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2026-04-09: | Advisory disclosed |
| 2026-04-09: | VulDB entry created |
| 2026-04-09: | VulDB entry last update |
Credits
tnn2026 (VulDB User)
References
vuldb.com/vuln/356617 (VDB-356617 | code-projects Vehicle Showroom Management System VehicleDetailsFunction.php sql injection)
vuldb.com/vuln/356617/cti (VDB-356617 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/796201 (Submit #796201 | code-projects Vehicle Showroom Management System V1.0 SQL Injection)
github.com/TAnNbR/CVE/issues/3
code-projects.org/