PT-2026-32228 · Code Projects · Vehicle Showroom Management System

Huahuan

·

Published

2026-04-13

·

Updated

2026-04-13

·

CVE-2026-6152

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/StaffAddingFunction.php. This manipulation of the argument STAFF ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6152

Affected Products

Vehicle Showroom Management System