CVE-2026-6037: code-projects Vehicle Showroom Management System AddVehicleFunction.php sql injection
A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function of the file /util/AddVehicleFunction.php. This manipulation of the argument BRANCHID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6037?
CVE-2026-6037 has been classified with a high severity level due to its potential for SQL injection exploitation.
How do I fix CVE-2026-6037?
To fix CVE-2026-6037, validate and sanitize user inputs in the AddVehicleFunction.php file to prevent SQL injection.
What are the potential impacts of CVE-2026-6037?
The potential impacts of CVE-2026-6037 include unauthorized access to the database, data manipulation, and data exposure.
Which software versions are affected by CVE-2026-6037?
CVE-2026-6037 specifically affects version 1.0 of the Code-Projects Vehicle Showroom Management System.
Is CVE-2026-6037 easy to exploit?
Yes, CVE-2026-6037 is considered easy to exploit for cyber attackers familiar with SQL injection techniques.