CVE-2026-6166 is a SQL injection vulnerability in code-projects Vehicle Showroom Management System version 1.0, specifically within the /util/UpdateVehicleFunction.php file where the VEHICLE_ID parameter is inadequately sanitized. This flaw allows attackers to manipulate database queries and potentially compromise data confidentiality and integrity. The vulnerability affects any deployment of this vehicle management system without patches applied. The vulnerability carries a CVSS 3.1 score of 7.3 (HIGH severity) and requires no authentication or user interaction for exploitation. It can be initiated remotely over a network with low attack complexity, resulting in potential unauthorized access to sensitive information and limited system modification capabilities. The FAUCET Risk Score of 37.0/100 reflects moderate organizational risk. Regarding exploitation status, the vulnerability has been publicly disclosed, which increases the risk of malicious use. However, it is not currently listed in the CISA Known Exploited Vulnerabilities catalog and shows minimal community attention based on its low EPSS score of 0.00039. Organizations using this system should nevertheless prioritize patching due to the public disclosure and straightforward exploitation requirements.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Code-Projects | Vehicle Showroom Management System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.