PT-2026-30595 · Projectworlds · Car Rental System

·

CVE-2026-5645

·

Published

2026-04-06

·

Updated

2026-04-28

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions projectworlds Car Rental System version 1.0
Description A weakness exists in projectworlds Car Rental System 1.0. The issue affects an unknown functionality within the /pay.php file of the Parameter Handler component. Manipulation of the mpesa argument can lead to SQL injection, allowing for remote attacks. The exploit is publicly available.
Recommendations Update to a newer version of projectworlds Car Rental System that addresses this vulnerability. As a temporary workaround, restrict access to the /pay.php file or disable the Parameter Handler component until a patch is available. Avoid using the mpesa parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5645

Affected Products

Car Rental System