SQL Injection Vulnerability in Das Parking Management System by a Remote Attack
CVE-2025-6118
What is CVE-2025-6118?
A SQL injection vulnerability exists in the Das Parking Management System version 6.2.0, specifically within the API component processing the /vehicle/search endpoint. The manipulation of the 'vehicleTypeCode' argument enables remote attackers to execute arbitrary SQL commands. This flaw can be exploited to compromise the database and access sensitive information, highlighting the importance of proper input validation and security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Parking Management System 停车场管理系统 6.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
