PT-2026-47008 · Code Projects · Vehicle Management System

Imad Alvi

·

Published

2026-06-05

·

Updated

2026-06-05

·

CVE-2026-11344

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration Form. Performing a manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used.

Exploit

Fix

Unrestricted File Upload

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-11344

Affected Products

Vehicle Management System