LOW🇵🇱 Wersja polska

CVE-2025-9847

CVSS 2.1v4.0pub. 2025-09-03upd. 2026-04-29

A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the argument uimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Scriptandtools Real Estate Management System

    APP
    Scriptandtools
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-9848MEDIUM5.5same product

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected e...

CVE-2025-5128MEDIUM6.9same product

A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0....

CVE-2025-6329LOW2.1same product

W Real Estate Management System 1.0 firmy ScriptAndTools odkryto podatność krytyczną w pliku userdelete.php ko...

CVE-2025-4064MEDIUM6.9same vendor

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. Th...

CVE-2025-4065MEDIUM6.9same vendor

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This...