Impact
A flaw in the BookVehicleFunction.php component of code‑projects Vehicle Showroom Management System 1.0 allows attackers to manipulate the BRANCH_ID argument, leading to an unsanitized SQL query. This remote SQL injection can be leveraged to read, modify, or delete database contents, creating a risk of data tampering and loss of confidentiality. The weakness aligns with CWE‑89, unsupported user input in SQL statements.
Affected Systems
The vulnerability affects the Vehicle Showroom Management System, version 1.0, released by code‑projects. No additional affected versions are listed, and the flaw is tied specifically to the /util/BookVehicleFunction.php file.
Risk and Exploitability
The CVSS v3 score of 6.9 indicates a medium‑to‑high impact. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can execute the exploit remotely, and published proof‑of‑concept code exists. Given these conditions, the likelihood of exploitation is moderate, and organizations running the vulnerable product should prioritize remediation.
OpenCVE Enrichment