PT-2026-43261 · Unknown · Parking Management System

·

CVE-2026-9551

·

Published

2026-05-26

·

Updated

2026-05-26

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Das Parking Management System version 6.2.0
Description Remote SQL injection is possible via the manipulation of the Value argument within the xp cmdshell() function of the 'ParkingRecord/ExportParkingRecords' API endpoint. SQL injection is a technique where an attacker inserts malicious SQL code into a query, allowing them to manipulate the database.
Recommendations As a temporary workaround, restrict access to the 'ParkingRecord/ExportParkingRecords' API endpoint or disable the xp cmdshell() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9551

Affected Products

Parking Management System