Impact
The vulnerability resides in the Vehicle Showroom Management System, where an attacker can inject SQL through the VEHICLE_ID parameter within UpdateVehicleFunction.php. This flaw allows unauthorized modification or extraction of data from the underlying database, compromising confidentiality and integrity of vehicle records. The weakness corresponds to improper handling of user input before database use, characteristic of SQL injection vulnerabilities.
Affected Systems
code-projects Vehicle Showroom Management System version 1.0 is affected. No other product or version information is available from the CNA data.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium to high severity, and the lack of a KEV listing suggests no confirmed large‑scale exploitation yet. The attack can be performed remotely, as the vulnerable file is accessed via a web request. Exploitation requires only supply of a malicious VEHICLE_ID value; no additional privileges or complex steps are reported. The probability of exploitation is unknown due to missing EPSS data, but the publicly disclosed nature of the exploit increases the risk.
OpenCVE Enrichment