{"id":"CVE-2026-85516","title":"code-projects Vehicle Management System busprofile.php sql injection","summary":"A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possibl…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","cvssSource":"cna","cwe":["CWE-89","CWE-74"],"vendor":"code-projects","product":"Vehicle Management System","affected":["vehicle_management_system 1.0"],"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-11T20:03:27.919056Z"},"exploitAvailable":true,"published":"2026-09-04","updated":"2026-09-11","sourceUpdated":"2026-09-11T20:37:35.916Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-85516","references":[{"url":"https://vuldb.com/vuln/398680","label":"VDB-398680 | code-projects Vehicle Management System busprofile.php sql injection"},{"url":"https://vuldb.com/vuln/398680/cti","label":"VDB-398680 | CTI Indicators (IOB, IOC, TTP, IOA)"},{"url":"https://vuldb.com/cve/CVE-2026-85516","label":"CVE-2026-85516 | CVE Analysis and Report"},{"url":"https://vuldb.com/submit/895112","label":"Submit #895112 | code-projects Vehicle Management System in PHP 1.0 SQL Injection"},{"url":"https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/SQL%20Injection%20Vulnerability%20in%20Vehicle%20Management%20System%20%60busid%60%20Parameter.md"},{"url":"https://code-projects.org/"}],"tags":["cve.org","exploit-available"],"epss":0.00412,"epssPercentile":0.35124,"ingestedAt":"2026-09-14T11:11:19.879Z","slug":"CVE-2026-85516","body":"## Overview\n\nA vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.\n\n## Affected\n\n- `vehicle_management_system 1.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":40.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}