HOMEVULNERABILITIESVENDORSCar Rental Management System Project

Car Rental Management System ProjectCVEs & Vulnerabilities

15 CVEs affecting Car Rental Management System Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

car rental management system 15
CVE-2020-29227KEVCRITICALin the wild

An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.

11 Apr 2026
9.8
CVSS
CVE-2022-32019CRITICAL

Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax.php?action=save_car.

2 Jun 2022
9.8
CVSS
CVE-2022-32028HIGH

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32027HIGH

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/index.php?page=manage_car&id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32026HIGH

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32025HIGH

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32024HIGH

Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32022HIGH

Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.

2 Jun 2022
7.2
CVSS
CVE-2022-32021HIGH

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_movement.php?id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32020CRITICAL

Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via ip/car-rental-management-system/admin/ajax.php?action=save_settings.

2 Jun 2022
9.8
CVSS
CVE-2022-29318HIGH

An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

11 May 2022
7.2
CVSS
CVE-2021-46005MEDIUM

Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter.

18 Jan 2022
5.4
CVSS
CVE-2020-29287CRITICAL

An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.

3 Dec 2020
9.8
CVSS
CVE-2020-27956CRITICAL

An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).

28 Oct 2020
9.8
CVSS
CVE-2020-23832MEDIUM

A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.

6 Oct 2020
6.1
CVSS
← PrevPage 1 / 1Next →
Car Rental Management System Project CVEs & Vulnerabilities — 15 Tracked