CVE-2026-5634
Published: 06 April 2026
Summary
CVE-2026-5634 is a medium-severity Injection (CWE-74) vulnerability. Its CVSS base score is 6.9 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 12.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).
Deeper analysis
CVE-2026-5634 is a SQL injection vulnerability (CWE-74, CWE-89) affecting projectworlds Car Rental Project version 1.0. The flaw resides in an unknown functionality of the file /book_car.php within the Parameter Handler component, where manipulation of the 'fname' argument enables SQL injection.
With a CVSS v3.1 base score of 7.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L), the vulnerability allows remote attackers with no privileges or user interaction to exploit it over the network with low complexity. Successful exploitation can result in low impacts to confidentiality, integrity, and availability, such as unauthorized data access, modification, or disruption.
Advisories and further details, including potential mitigation steps, are available in the following references: https://github.com/eqiya17/collection-of-vulnerabilities/issues/12, https://vuldb.com/submit/785863, https://vuldb.com/vuln/355422, and https://vuldb.com/vuln/355422/cti. A public exploit is available and might be used.
The vulnerability was published on 2026-04-06T08:16:39.700.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-19200
Vulnerability details
A vulnerability was identified in projectworlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /book_car.php of the component Parameter Handler. The manipulation of the argument fname leads to sql injection. The attack can…
more
be initiated remotely. The exploit is publicly available and might be used.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
SQL injection in public-facing web app (/book_car.php) directly enables remote exploitation of the application without auth or interaction, matching T1190.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly prevents SQL injection by requiring validation of untrusted inputs like the 'fname' parameter in /book_car.php.
Requires timely identification, reporting, and correction of the specific SQL injection flaw in the Parameter Handler component.
Boundary protection with web application firewalls can inspect and block SQL injection payloads targeting the 'fname' argument remotely.