CVE-2026-6149: code-projects Vehicle Showroom Management System BookVehicleFunction.php sql injection
A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Affected by this issue is some unknown functionality of the file /util/BookVehicleFunction.php. Executing a manipulation of the argument BRANCHID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6149?
The severity of CVE-2026-6149 is rated medium with a score of 5.5.
How do I fix CVE-2026-6149?
To fix CVE-2026-6149, update the Code-projects Vehicle Showroom Management System to the latest version that addresses the SQL injection vulnerability.
What type of vulnerability is CVE-2026-6149?
CVE-2026-6149 is classified as an SQL Injection vulnerability affecting the BookVehicleFunction.php file.
Can CVE-2026-6149 be exploited remotely?
Yes, CVE-2026-6149 can be exploited remotely by manipulating the BRANCH_ID argument.
What is the impact of CVE-2026-6149?
The impact of CVE-2026-6149 includes potential unauthorized access to the database and exposure of sensitive data.