Impact
A remote attacker can exploit a flaw in the busprofile.php module of the 1.0 Vehicle Management System to inject arbitrary SQL via the busid parameter. This injection permits the attacker to read, modify, or delete database records, compromising the integrity and confidentiality of vehicle data.
Affected Systems
The affected product is code-projects Vehicle Management System version 1.0, specifically the busprofile.php component. The vulnerability is tied to the busid parameter handling within that file.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity. The exploit is publicly available and can be triggered remotely through normal HTTP requests, but no EPSS information is reported. It is not listed in the CISA KEV catalog, so while known exploitation is not confirmed, the remote and public nature of the attack vector creates a significant risk that warrants immediate attention.
OpenCVE Enrichment