Executive brief
A security vulnerability has been identified in the Das Parking Management System, a software platform used to manage vehicle entry, exit, and records in parking facilities. An attacker can exploit this flaw to gain unauthorized access to the underlying database and potentially execute system-level commands. This could lead to the theft of sensitive parking records, disruption of facility operations, or full compromise of the management server.
Technical details
A SQL injection vulnerability exists in Das Parking Management System 6.2.0 within the API endpoint 'ParkingRecord/ExportParkingRecords'. The vulnerability is located in the handling of the 'Value' argument, which is improperly neutralized before being used in a database query. Specifically, the advisory notes the involvement of the 'xp_cmdshell' function, suggesting that an attacker could leverage this injection to execute arbitrary operating system commands on the host server. The attack can be performed remotely without authentication. As of the disclosure date, the vendor has not responded to reports, and public exploit code is reportedly available.
Affected products
- Das Parking Management System (停车场管理系统) 6.2.0
Timeline
- 2026-05-26: advisory: NVD published the CVE record based on VulDB data.
- 2026-05-26: disclosed: Public disclosure of the vulnerability and exploit.