{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-10243", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-05-31T10:12:00.665Z", "datePublished": "2026-06-01T09:00:13.192Z", "dateUpdated": "2026-06-01T15:23:18.984Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-06-01T09:00:13.192Z" }, "title": "code-projects Smart Parking System Admin Endpoint missing authentication", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-306", "lang": "en", "description": "Missing Authentication" } ] }, { "descriptions": [ { "type": "CWE", "cweId": "CWE-287", "lang": "en", "description": "Improper Authentication" } ] } ], "affected": [ { "vendor": "code-projects", "product": "Smart Parking System", "versions": [ { "version": "1.0", "status": "affected" } ], "cpes": [ "cpe:2.3:a:code-projects:smart_parking_system:*:*:*:*:*:*:*:*" ], "modules": [ "Admin Endpoint" ] } ], "descriptions": [ { "lang": "en", "value": "A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 6.9, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 7.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "HIGH" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 7.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "HIGH" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 7.5, "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR" } } ], "timeline": [ { "time": "2026-05-31T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-05-31T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-05-31T12:17:08.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "imad alvi (VulDB User)", "type": "reporter" } ], "references": [ { "url": "https://vuldb.com/vuln/367521", "name": "VDB-367521 | code-projects Smart Parking System Admin Endpoint missing authentication", "tags": [ "vdb-entry" ] }, { "url": "https://vuldb.com/vuln/367521/cti", "name": "VDB-367521 | CTI Indicators (IOB, IOC)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/cve/CVE-2026-10243", "name": "CVE-2026-10243 | CVE Analysis and Report", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/823871", "name": "Submit #823871 | code-projects Smart Parking System In PHP With Source Code 1.0 Improper Access Controls", "tags": [ "third-party-advisory" ] }, { "url": "https://github.com/Xmyronn/smart-parking-system-broken-access.git", "tags": [ "exploit" ] }, { "url": "https://code-projects.org/", "tags": [ "product" ] } ], "tags": [ "x_freeware" ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-06-01T15:00:26.860506Z", "id": "CVE-2026-10243", "options": [ { "Exploitation": "poc" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-06-01T15:23:18.984Z" } } ] } }