CVE-2026-6038
Published: 10 April 2026
Summary
CVE-2026-6038 is a medium-severity Injection (CWE-74) vulnerability in Code Projects (inferred from references). Its CVSS base score is 6.9 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 13.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).
Deeper analysis
CVE-2026-6038 is a SQL injection vulnerability (CWE-74, CWE-89) in code-projects Vehicle Showroom Management System 1.0. It affects an unknown function within the file /util/RegisterCustomerFunction.php, where manipulation of the BRANCH_ID argument enables SQL code injection. The issue was published on 2026-04-10 and carries a CVSS v3.1 base score of 7.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L), indicating high severity with network accessibility and low complexity.
Unauthenticated remote attackers can exploit this vulnerability without privileges or user interaction. By crafting malicious input for the BRANCH_ID parameter, attackers can execute arbitrary SQL queries, potentially leading to limited impacts on confidentiality, integrity, and availability, such as data extraction, modification, or disruption. A public exploit is available and might be used in attacks.
Advisories and further details are documented in references including VulDB entries (vuldb.com/vuln/356619), a GitHub issue (github.com/mrpgi/cve/issues/3), and the vendor site (code-projects.org). Practitioners should consult these for any patch availability or mitigation guidance.
The exploit's public availability increases the risk of real-world exploitation against exposed instances of the affected software.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-21352
Vulnerability details
A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function of the file /util/RegisterCustomerFunction.php. Such manipulation of the argument BRANCH_ID leads to sql injection. The attack may be performed from remote. The exploit is…
more
publicly available and might be used.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
SQL injection in public-facing web app (RegisterCustomerFunction.php) directly enables T1190 for unauthenticated remote exploitation and arbitrary query execution.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly prevents SQL injection attacks by enforcing validation of untrusted inputs like the BRANCH_ID parameter in RegisterCustomerFunction.php.
Remediates the specific SQL injection flaw in the Vehicle Showroom Management System through timely patching or mitigation.
Detects the SQL injection vulnerability via vulnerability scanning and supports remediation of exposed instances.