Vulnerability Description
A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the argument uname causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Projectworlds | Car Rental Project | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/eqiya17/collection-of-vulnerabilities/issues/5ExploitIssue TrackingMitigation
- https://vuldb.com/submit/781665Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/354746Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/354746/ctiPermissions RequiredVDB Entry
FAQ
What is CVE-2026-5368?
CVE-2026-5368 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the ...
How severe is CVE-2026-5368?
CVE-2026-5368 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5368?
Check the references section above for vendor advisories and patch information. Affected products include: Projectworlds Car Rental Project.