MEDIUM🇵🇱 Wersja polska

CVE-2025-5128

CVSS 6.9v4.0pub. 2025-05-24upd. 2025-07-11

A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected is an unknown function of the file /admin/ of the component Admin Login Panel. The manipulation of the argument Password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Scriptandtools Real Estate Management System

    APP
    Scriptandtools
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-9848MEDIUM5.5same product

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected e...

CVE-2025-9847LOW2.1same product

Odkryta została podatność w ScriptAndTools Real Estate Management System 1.0. Podatność dotyczy nieznanej funk...

CVE-2025-6329LOW2.1same product

W Real Estate Management System 1.0 firmy ScriptAndTools odkryto podatność krytyczną w pliku userdelete.php ko...

CVE-2025-4064MEDIUM6.9same vendor

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. Th...

CVE-2025-4065MEDIUM6.9same vendor

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This...