PT-2026-30583 · Projectworlds · Car Rental System

Wangyiqi

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-5637

CVSS v2.0

7.5

High

AV:N/AC:L/Au:N/C:P/I:P/A:P
A security vulnerability has been detected in projectworlds Car Rental System 1.0. This vulnerability affects unknown code of the file /message admin.php of the component Parameter Handler. Such manipulation of the argument Message leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-5637

Affected Products

Car Rental System