Junglewise Threat Intelligence

CVE-2026-14735: code-projects Smart Parking System SQL injection in parkings.php

CVE-2026-14735 · Severity: high · CVSS 7.3 · Published 2026-07-05

Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the Smart Parking System 1.0, a software package used to manage parking facility operations. An attacker can remotely exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive information or disruption of parking services. This issue is particularly serious because it can be triggered over the internet without requiring any user login credentials.

Technical details

A SQL injection vulnerability exists in code-projects Smart Parking System 1.0 within the /parkings/parkings.php component. The application fails to properly sanitize the 'street', 'city', and 'status' arguments before incorporating them into SQL queries. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to the vulnerable endpoint. Successful exploitation allows for arbitrary database manipulation, which may lead to unauthorized data retrieval, modification, or potentially arbitrary file reading as indicated by associated research. Public exploit code has been disclosed.

Affected products

  • code-projects Smart Parking System 1.0

Timeline

  • 2026-07-05: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-07-05: advisory: NVD and VulDB published the advisory.

References

Related threats