Junglewise Threat Intelligence

CVE-2026-5634: projectworlds Car Rental Project SQL injection in book_car.php

CVE-2026-5634 · Severity: high · CVSS 7.3 · Published 2026-04-06

Vendors: Projectworlds.

Executive brief

A security vulnerability exists in the projectworlds Car Rental Project, a web application used for managing vehicle rentals. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of customer information or disruption of the rental service. This attack can be performed remotely without requiring any user login or special permissions.

Technical details

A SQL injection vulnerability exists in projectworlds Car Rental Project 1.0 within the 'Parameter Handler' component of the /book_car.php file. The root cause is the improper neutralization of special elements used in an SQL command, specifically affecting the 'fname' POST parameter. A remote, unauthenticated attacker can exploit this by sending crafted SQL queries, such as time-based blind payloads, to manipulate database operations. This can result in unauthorized data retrieval, modification, or deletion. A public proof-of-concept (PoC) using sqlmap has been disclosed, confirming the vulnerability is exploitable via network-based attacks without user interaction.

Affected products

  • projectworlds Car Rental Project 1.0

Timeline

  • 2026-03-23: disclosed: Initial disclosure on GitHub by eqiya17
  • 2026-04-06: advisory: CVE published and VulDB entry created

References