CVE-2026-5368: projectworlds Car Rental Project Parameter login.php sql injection
A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the argument uname causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5368?
CVE-2026-5368 is classified as a high-severity vulnerability due to the potential for SQL injection, which can lead to unauthorized data access.
How do I fix CVE-2026-5368?
To fix CVE-2026-5368, validate and sanitize user inputs in the login.php file to prevent SQL injection attacks.
What is the main impact of CVE-2026-5368?
The main impact of CVE-2026-5368 is the possibility of attackers executing arbitrary SQL commands, compromising the security of the database.
Which software is affected by CVE-2026-5368?
CVE-2026-5368 affects the Projectworlds Car Rental Project version 1.0.
Can CVE-2026-5368 be exploited remotely?
Yes, CVE-2026-5368 can be exploited remotely by sending specially crafted inputs to the login.php file.