Impact
This vulnerability arises from improper handling of the BRANCH_ID parameter within the RegisterCustomerFunction.php module of the Vehicle Showroom Management System. Exploitation allows an attacker to inject arbitrary SQL statements, potentially leading to unauthorized disclosure, modification, or destruction of critical business data. The attack can compromise confidentiality, integrity, and availability of the underlying database.
Affected Systems
The affected product is code-projects Vehicle Showroom Management System, version 1.0. The vulnerability is located in the /util/RegisterCustomerFunction.php file and affects any deployment of this version that accepts user input for BRANCH_ID.
Risk and Exploitability
The CVSS score for this issue is 6.9, indicating a moderate severity. No EPSS score is available, and the vulnerability does not appear in the CISA KEV catalog, but publicly available exploit code exists, signaling that attacks can occur on the open internet. Attackers can craft an HTTP request with a malicious BRANCH_ID value and execute it remotely, potentially gaining full control over the database content.
OpenCVE Enrichment