CVE-2026-6148Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in code-projects Vehicle Showroom Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /util/MonthTotalReportUpdateFunction.php. Performing a manipulation of the argument BRANCH_ID results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-13); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-13: 3Mentions · 2026-04-22: 1Technical Details · 2026-04-13: 2Technical Details · 2026-04-22: 104-1304-22
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-133
Disclosure2General1
2026-04-221
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6148 SQL Injection in Code-Projects Vehicle Showroom Management System ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6148 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post announces CVE‑2026‑6148 as a SQL injection vulnerability in Code‑Projects Vehicle Showroom Management System, with only a brief identification and a link to a vulnerability database, but no additional exploit or mitigation details.

    0100077
    4.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    🚨 HIGH Severity Alert CVE-2026-6148 (CVSS 7.3): SQL Injection in Vehicle Showroom Management System 1.0 Exploit publicly available. Remote attack, no auth required. Affected: /util/MonthTotalReportUpdateFunction[.]php #CVE #Vulnerability #PatchNow https://t.co/W6LIDowCmt

    Post summary

    This alert announces a high‑severity SQL injection vulnerability (CVE‑2026‑6148) in Vehicle Showroom Management System 1.0, noting that an exploit is publicly available and requires no authentication. No patch or mitigation details are provided, nor is there evidence of active exploitation.

    0000048
    26 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6148 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6148 #CVE-2026-6148 #CVE #High #CyberSecurity #InfoSec https://t.co/kKgeZJTPxq

    Post summary

    A brief alert announcing CVE‑2026‑6148 with a severity of 7.3 and high risk level, but lacking specific technical details, exploit code, or patch information.

    0000036
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6148 A vulnerability was detected in code-projects Vehicle Showroom Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /util/Month… https://www.cve.org/CVERecord?id=CVE-2026-6148

    Post summary

    The text notes the existence of CVE-2026-6148 with a minimal description, primarily indicating a potential issue in /util/Month, but offers no additional technical, exploit, or remediation details.

    0000052
    57.1K followersView on X

Explore more