Impact
The SourceCodester Vehicle Parking Area Management System version 1.0 contains a SQL injection vulnerability in the file /parking/manage_location.php. The flaw allows an attacker to manipulate the database query embedded in this script, potentially leading to disclosure or unauthorized changes of parking and user data. This weakness is identified as CWE‑89.
Affected Systems
The affected system is the SourceCodester Vehicle Parking Area Management System, version 1.0. No additional vendor or product information is supplied beyond the presence of the vulnerability in the manage_location module.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, while the EPSS score of <1% indicates a low probability of exploitation at present. The description does not specify whether authentication is required or detail the exact attack vector, only that the flaw exists in a web‑accessible PHP file. The vulnerability is not listed in the CISA KEV catalog, so no publicly documented exploits are known. If the location management page is exposed to the Internet, the combination of high severity and a web‑based entry point warrants reasonable vigilance.
OpenCVE Enrichment