CVE-2026-6035 is a cross-site scripting (XSS) vulnerability in code-projects Vehicle Showroom Management System version 1.0, specifically within the ServiceAndSalesReport.php file where the BRANCH_ID parameter is inadequately sanitized. This allows unauthenticated remote attackers to inject malicious scripts through a manipulated argument. The vulnerability affects the integrity of the application and can compromise user sessions or data. The vulnerability has a CVSS v3.1 severity score of 4.3 (Medium), with a network-based attack vector requiring minimal complexity and user interaction to trigger. The attack does not require authentication or elevated privileges, though successful exploitation depends on user action. The impact is limited to integrity violations with no confidentiality or availability compromise. Exploitation is currently limited in scope. While the vulnerability details have been publicly disclosed, the EPSS score of 0.00035 indicates an extremely low probability of active exploitation in the wild, and the CVE is not listed on the Known Exploited Vulnerabilities catalog or tracked as part of security community hotlists. Organizations running this software should still apply available patches, but this is not an imminent threat requiring emergency remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Code-Projects | Vehicle Showroom Management System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.