CVE-2026-5368

HIGH

projectworlds Car Rental Project Parameter login.php sql injection

Title source: cna
STIX 2.1

Description

A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the argument uname causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

References (4)

Core 4
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-354746 | projectworlds Car Rental Project Parameter login.php sql injection
https://vuldb.com/vuln/354746
Signature, Permissions Required signature permissions-required
VDB-354746 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/354746/cti
Third Party Advisory third-party-advisory
Submit #781665 | projectworlds Car Rental v1.0 SQL Injection
https://vuldb.com/submit/781665

Scores

CVSS v3 7.3
EPSS 0.0033
EPSS Percentile 24.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (2)
projectworlds/Car Rental Project 1.0
projectworlds/car_rental_project 1.0
Published Apr 02, 2026
Tracked Since Apr 02, 2026