6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. The manipulation of the argument Value leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Basic Information
ID
CVE-2026-9551
Source
VulDB
Published
May 26, 2026 at 13:45
Modified
May 26, 2026 at 15:21
Affected Product
Vendor
Das
Product
Parking Management System 停车场管理系统
Version
6.2.0
Affected Versions
Das Parking Management System 停车场管理系统 6.2.0