Junglewise Threat Intelligence

CVE-2026-6038: code-projects Vehicle Showroom Management System SQL injection in RegisterCustomerFunction.php

CVE-2026-6038 · Severity: high · CVSS 7.3 · Published 2026-04-10

Vendors: Code-Projects.

Executive brief

A vulnerability exists in the Vehicle Showroom Management System, a web application used for managing automotive dealership operations. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of customer information, tampering with vehicle records, or disruption of business operations. This attack can be carried out remotely without requiring any user credentials.

Technical details

A SQL injection vulnerability exists in the /util/RegisterCustomerFunction.php component of the Vehicle Showroom Management System 1.0. The root cause is the improper neutralization of the 'BRANCH_ID' POST parameter before it is used in a SQL query. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to perform boolean-based or time-based blind SQL injection. Successful exploitation allows for unauthorized database access, sensitive data exfiltration, and potential modification of database records. A public exploit (PoC) using sqlmap has been disclosed.

Affected products

  • code-projects Vehicle Showroom Management System 1.0

Timeline

  • 2026-04-03: disclosed: Initial disclosure on GitHub by security researchers
  • 2026-04-10: advisory: CVE published and VulDB entry created

References