Executive brief
A security vulnerability has been identified in the Das Parking Management System, a software solution used to manage vehicle entry, exit, and billing in parking facilities. An attacker can remotely exploit this flaw to gain unauthorized access to the system's database, potentially leading to the theft of sensitive operational data or disruption of parking services. Because a public exploit is available and the vendor has not yet responded, organizations using this system should take immediate steps to restrict network access to the management interface.
Technical details
A SQL injection vulnerability exists in Das Parking Management System version 6.2.0. The flaw is located within the Search API endpoint and is triggered by improper neutralization of the 'Value' argument. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the endpoint to execute arbitrary SQL commands against the backend database. This can result in unauthorized data retrieval, modification, or deletion. A public exploit has been released, and as of the publication date, the vendor has not provided a patch or official response.
Affected products
- Das Parking Management System (停车场管理系统) 6.2.0
Timeline
- 2026-05-26: disclosed: Vulnerability disclosed via VulDB and NVD
- 2026-05-26: advisory