Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6038

25
FAUCET Score

CVE-2026-6038 is a SQL injection vulnerability affecting code-projects Vehicle Showroom Management System version 1.0, specifically within the /util/RegisterCustomerFunction.php file where the BRANCH_ID parameter fails to properly sanitize user input. This flaw allows attackers to manipulate database queries through remote network access with no authentication required. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector, low complexity, and no user interaction needed, resulting in potential compromise of data confidentiality, integrity, and availability. The FAUCET Risk Score of 47.0 out of 100 indicates a moderate-to-high risk profile requiring prompt remediation. Although exploit code is publicly available, the vulnerability is not currently listed in the Known Exploited Vulnerabilities catalog and shows minimal community adoption based on the low EPSS score of 0.0004. Organizations running this showroom management system should prioritize patching immediately given the public availability of exploit code and the remote, unauthenticated nature of the attack.

Impacted Technologies

VendorProductVersion(s)CPE
Code-ProjectsVehicle Showroom Management System
1.0CNA affected

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 3rd percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

code-projects.org
github.com / mrpgi/cve/issues/3
vuldb.com / submit/796281
vuldb.com / vuln/356619
vuldb.com / vuln/356619/cti