CVE-2026-6034: code-projects Vehicle Showroom Management System ProfitAndLossReport.php cross site scripting
A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /BranchManagement/ProfitAndLossReport.php. Executing a manipulation of the argument BRANCHID can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6034?
CVE-2026-6034 has been classified as a high-severity vulnerability due to its potential for cross-site scripting attacks.
How can I mitigate CVE-2026-6034?
To mitigate CVE-2026-6034, validate and sanitize all user inputs in the ProfitAndLossReport.php file to prevent injection of malicious scripts.
What is the impact of CVE-2026-6034 on the Vehicle Showroom Management System?
CVE-2026-6034 allows attackers to execute arbitrary JavaScript in the context of the user’s session, which can lead to data theft or session hijacking.
Is there a patch available for CVE-2026-6034?
As of now, there is no official patch released for CVE-2026-6034, but users are advised to implement input sanitization immediately.
Which version of the Vehicle Showroom Management System is affected by CVE-2026-6034?
CVE-2026-6034 affects version 1.0 of the Vehicle Showroom Management System.