CVE-2026-6148: code-projects Vehicle Showroom Management System MonthTotalReportUpdateFunction.php sql injection
A vulnerability was detected in code-projects Vehicle Showroom Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /util/MonthTotalReportUpdateFunction.php. Performing a manipulation of the argument BRANCHID results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6148?
The severity of CVE-2026-6148 is medium with a score of 5.5.
How do I fix CVE-2026-6148?
To fix CVE-2026-6148, ensure that input to the 'BRANCH_ID' parameter is properly sanitized and validated to prevent SQL injection.
What type of vulnerability is CVE-2026-6148?
CVE-2026-6148 is classified as a SQL Injection vulnerability.
Which component is affected by CVE-2026-6148?
CVE-2026-6148 affects the 'MonthTotalReportUpdateFunction.php' file in the Code-projects Vehicle Showroom Management System.
Can CVE-2026-6148 be exploited remotely?
Yes, CVE-2026-6148 can be exploited remotely due to its nature of SQL injection through a manipulated argument.