CVE-2026-5645Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /pay.php of the component Parameter Handler. Executing a manipulation of the argument mpesa can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-04-06); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-04-06: 5Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-28: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-06: 3Technical Details · 2026-04-28: 104-0604-28
Signal classification3 categories
Disclosure
233.3%
General
233.3%
Patch
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-065
Disclosure2General2Patch1
2026-04-281
Patch1
Full discourse6 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CVE-2026-5645 | CVSS 7.3 HIGH SQL Injection in Car Rental System 1.0 (/pay[.]php). Remote exploit publicly available. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR

    Post summary

    The post announces a high‑severity SQL Injection in Car Rental System 1.0, urges immediate patching, and notes the availability of a public exploit.

    0101039
    1 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5645 A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /pay.php of the component … https://www.cve.org/CVERecord?id=CVE-2026-5645

    Post summary

    The notice identifies a weakness in projectworlds Car Rental System 1.0 but provides no further technical, exploit, or mitigation details.

    00010324
    57.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2026-5645 (CVSS 7.3) - SQL Injection in projectworlds Car Rental System 1.0 via /pay[.]php. Exploit publicly available. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/EHh1bTuwTo

    Post summary

    A new high‑severity SQL injection vulnerability (CVE‑2026‑5645) in ProjectWorlds Car Rental System 1.0 is publicly exploitable; immediate patching is urged.

    0000049
    27 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5645 SQL Injection in ProjectWorlds Car Rental System 1.0 Parameter Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5645

    Post summary

    The statement announces CVE-2026-5645, a SQL injection flaw in ProjectWorlds Car Rental System 1.0, offering a link for more details but providing no information on exploit code, active attacks, patches, or debunking.

    0000045
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5645 - projectworlds Car Rental System Parameter pay.php sql injection Intel Report: https://ift.tt/KJ05Ne2

    Post summary

    An alert announces CVE‑2026‑5645 as a SQL injection flaw in projectworlds Car Rental System’s pay.php file, but offers no PoC, exploit, or patch information.

    0000038
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5645 A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /pay.php of the component … https://www.cve.org/CVERecord?id=CVE-2026-5645 ----- Traducción: CVE-2026-5645 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑5645 for projectworlds Car Rental System 1.0, noting an unspecified weakness in /pay.php without any PoC, exploit, or mitigation details.

    0000037
    67 followersView on X

Explore more