Junglewise Threat Intelligence

CVE-2026-11344: code-projects Vehicle Management System unrestricted upload in newdriver.php

CVE-2026-11344 · Severity: high · CVSS 7.3 · Published 2026-06-05

Technologies: Code-Projects Vehicle Management System. Vendors: Code-Projects.

Executive brief

A vulnerability exists in the Vehicle Management System, a software used for managing fleet and driver records. An attacker can upload malicious files to the server through the driver registration form without needing a username or password. This could allow an attacker to take complete control of the server, potentially leading to data theft or a total service shutdown.

Technical details

An unrestricted file upload vulnerability exists in code-projects Vehicle Management System 1.0 within the 'New Driver Registration Form' (newdriver.php). The application fails to perform session validation, allowing unauthenticated remote access to the registration endpoint. Furthermore, the 'photo' parameter does not implement file extension filtering or MIME type validation. An attacker can exploit this by uploading a PHP webshell disguised as a photo, which is then stored in the /picture/ directory. Accessing the uploaded file allows for arbitrary code execution with the privileges of the web server. A similar vulnerability is reported to exist in newvehicle.php.

Affected products

  • code-projects Vehicle Management System 1.0

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References

Related threats