CVE-2026-11344
A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration Form. Performing a manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used.
- Affected products
- Vehicle Management System
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- CVSS 3.1
- 7.3 HIGH
- EPSS
- 0.4% (29th percentile)
- Weakness
- CWE-284, CWE-434
- NVD status
- Deferred
- Published
- 2026-06-05
CVE-2026-11344 at NVD
1 known exploit for CVE-2026-11344
Proof-of-concept code and exploit modules indexed by Sploitus