CVE-2026-6038 is a SQL injection vulnerability affecting code-projects Vehicle Showroom Management System version 1.0, specifically within the /util/RegisterCustomerFunction.php file where the BRANCH_ID parameter fails to properly sanitize user input. This flaw allows attackers to manipulate database queries through remote network access with no authentication required. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector, low complexity, and no user interaction needed, resulting in potential compromise of data confidentiality, integrity, and availability. The FAUCET Risk Score of 47.0 out of 100 indicates a moderate-to-high risk profile requiring prompt remediation. Although exploit code is publicly available, the vulnerability is not currently listed in the Known Exploited Vulnerabilities catalog and shows minimal community adoption based on the low EPSS score of 0.0004. Organizations running this showroom management system should prioritize patching immediately given the public availability of exploit code and the remote, unauthenticated nature of the attack.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Code-Projects | Vehicle Showroom Management System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.