CVE-2026-6148 | code-projects Vehicle Showroom Management System 1.0 MonthTotalReportUpdateFunction.php BRANCH_ID sql injection
A vulnerability classified as critical has been found in code-projects Vehicle Showroom Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /util/MonthTotalReportUpdateFunction.php. Performing a manipulation of the argument BRANCH_ID results in sql injection.
This vulnerability is reported as CVE-2026-6148. The attack is possible to be carried out remotely. Moreover, an exploit is present.