LOW🇬🇧 English

CVE-2025-6329

CVSS 2.1v4.0pub. 2025-06-20upd. 2026-04-29

W Real Estate Management System 1.0 firmy ScriptAndTools odkryto podatność krytyczną w pliku userdelete.php komponentu User Delete Handler. Manipulacja parametrem ID umożliwia obejście autoryzacji, co pozwala na zdalne wykonanie ataku. Exploit został ujawniony publicznie.

Pokaż oryginał (EN)

A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file userdelete.php of the component User Delete Handler. The manipulation of the argument ID leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Scriptandtools Real Estate Management System

    APP
    Scriptandtools
    1.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2025-9848MEDIUM5.5ten sam produkt

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected e...

CVE-2025-5128MEDIUM6.9ten sam produkt

A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0....

CVE-2025-9847LOW2.1ten sam produkt

Odkryta została podatność w ScriptAndTools Real Estate Management System 1.0. Podatność dotyczy nieznanej funk...

CVE-2025-4064MEDIUM6.9ten sam vendor

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. Th...

CVE-2025-4065MEDIUM6.9ten sam vendor

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This...