Description
A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Value results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-05-26
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to inject and execute arbitrary SQL through the Search API endpoint by manipulating the Value parameter. The injection can be performed remotely and an exploit has been released to the public.

Affected Systems

Das Parking Management System (停车场管理系统) version 6.2.0 is affected. No other versions or products are reported as impacted.

Risk and Exploitability

The CVSS score is 6.9, indicating medium severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog. An exploit has been publicly released and the attack can be performed remotely, which increases the likelihood of exploitation in environments where the Search API is exposed.

Generated by OpenCVE AI on May 26, 2026 at 15:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify whether the deployed application is version 6.2.0; if so, isolate or disable the Search API endpoint from external access.
  • Implement input validation or a web application firewall rule that blocks malicious SQL patterns on the Value parameter.
  • Monitor database and application logs for anomalous queries and investigate any suspicious activity.
  • Engage with the vendor for a formal fix; if a patch is not forthcoming, plan to upgrade to a supported version or migrate to an alternative solution.

Generated by OpenCVE AI on May 26, 2026 at 15:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Das parking Management System
Vendors & Products Das parking Management System

Tue, 26 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Value results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Das Parking Management System 停车场管理系统 Search API Endpoint sql injection
First Time appeared Das
Das parking Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:das:parking_management_system_:*:*:*:*:*:*:*:*
Vendors & Products Das
Das parking Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Das Parking Management System Parking Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-26T15:20:14.420Z

Reserved: 2026-05-26T07:18:49.991Z

Link: CVE-2026-9552

cve-icon Vulnrichment

Updated: 2026-05-26T15:20:10.730Z

cve-icon NVD

Status : Deferred

Published: 2026-05-26T15:17:02.993

Modified: 2026-05-26T19:47:48.987

Link: CVE-2026-9552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T17:30:10Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')