Executive brief
A vulnerability exists in the Vehicle Showroom Management System, a web application used for managing automotive dealership operations. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of customer information or the modification of business records. This attack can be carried out remotely without requiring any user credentials or special access.
Technical details
A SQL injection vulnerability exists in code-projects Vehicle Showroom Management System 1.0 within the /util/PaymentStatusFunction.php component. The root cause is the improper neutralization of special elements used in an SQL command, specifically involving the 'CUSTOMER_ID' POST parameter. An unauthenticated remote attacker can send crafted SQL queries to the server to bypass authentication, leak sensitive database information, or modify data. The vulnerability supports multiple exploitation techniques including boolean-based blind, error-based, time-based blind, and UNION-based SQL injection. No login or prior authorization is required for exploitation.
Affected products
- code-projects Vehicle Showroom Management System 1.0
Timeline
- 2026-04-03: disclosed: Initial disclosure on GitHub issues
- 2026-04-13: advisory: NVD publication date