Impact
The vulnerability originates from the MonthTotalReportUpdateFunction.php script in Vehicle Showroom Management System 1.0. An attacker can manipulate the BRANCH_ID argument to inject arbitrary SQL because the input is not validated or escaped. This flaw allows direct tampering of or data extraction from the database, potentially compromising confidentiality, integrity, or availability of the system's data.
Affected Systems
Code-projects Vehicle Showroom Management System version 1.0 is affected. The security issue is confined to the MonthTotalReportUpdateFunction.php file, and no other versions or components are listed as vulnerable.
Risk and Exploitability
With a CVSS score of 6.9, the vulnerability is considered moderate. EPSS is not provided and it is not cataloged in KEV. Since it can be carried out remotely through web requests and an exploit is publicly available, attackers can exploit this flaw without authentication. The lack of an official patch or workaround increases the risk for systems exposed to untrusted networks.
OpenCVE Enrichment