CVE-2026-5634: projectworlds Car Rental Project Parameter book_car.php sql injection
A vulnerability was identified in projectworlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /book_car.php of the component Parameter Handler. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5634?
CVE-2026-5634 has a moderate severity rating due to its potential for SQL injection attacks.
How do I fix CVE-2026-5634?
To fix CVE-2026-5634, ensure that user input is properly sanitized and validated before being processed in the /book_car.php file.
What components are affected by CVE-2026-5634?
CVE-2026-5634 affects the Parameter Handler functionality of the projectworlds Car Rental Project version 1.0.
What type of attack can exploit CVE-2026-5634?
CVE-2026-5634 can be exploited through SQL injection attacks, allowing attackers to manipulate database queries.
Is there a patch available for CVE-2026-5634?
As of now, no official patch is available for CVE-2026-5634, so immediate mitigation practices should be implemented.