SourceCodester Vehicle Parking Area Management System version 1.0 contains a SQL Injection vulnerability in the /parking/view_parked_details.php file that allows authenticated attackers to manipulate database queries and potentially compromise the application's data integrity and confidentiality. The vulnerability carries a CVSS score of 7.2 (HIGH), requiring high-level privileges but offering no additional complexity, with the attack deliverable over the network resulting in high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation in the wild, as the vulnerability does not appear on the CISA Known Exploited Vulnerabilities list, and community attention remains minimal with a FAUCET Risk Score of 37.0 out of 100. The EPSS score of 0.000370 indicates a low probability of exploitation relative to other published vulnerabilities, suggesting this represents a lower near-term threat. Organizations running this system should prioritize patching once updates become available, particularly given the high-severity rating and the direct database access the vulnerability permits.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.