PT-2026-43261 · Unknown · Parking Management System

Bigbrother_Man

·

Published

2026-05-26

·

Updated

2026-05-26

·

CVE-2026-9551

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Das Parking Management System version 6.2.0
Description Remote SQL injection is possible via the manipulation of the Value argument within the xp cmdshell() function of the 'ParkingRecord/ExportParkingRecords' API endpoint. SQL injection is a technique where an attacker inserts malicious SQL code into a query, allowing them to manipulate the database.
Recommendations As a temporary workaround, restrict access to the 'ParkingRecord/ExportParkingRecords' API endpoint or disable the xp cmdshell() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-9551

Affected Products

Parking Management System