SourceCodester Vehicle Parking Area Management System version 1.0 contains a critical SQL Injection vulnerability in the /parking/manage_park.php file that allows unauthenticated attackers to manipulate database queries. This vulnerability affects the parking management system and could enable unauthorized access to sensitive parking data and system functions. The vulnerability has been assigned a CVSS 3.1 score of 9.8 (CRITICAL) with a network-based attack vector requiring no authentication, low attack complexity, and no user interaction. Successful exploitation could result in complete compromise of confidentiality, integrity, and availability of the affected system, allowing attackers to read, modify, or delete database records. There is currently no evidence of active exploitation in the wild, as the vulnerability does not appear on CISA's Known Exploited Vulnerabilities list and remains inactive on security hotlists. However, the extremely low EPSS score suggests limited real-world exploitation activity despite the critical severity rating. Organizations running this application should prioritize patching or implementing access controls while monitoring for exploitation attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.