Unknown · Real State Services · CVE-2026-13559
**Name of the Vulnerable Software and Affected Versions**
Real State Services version 1.0
**Description**
An issue exists in the `/single-list sale.php?action=add` endpoint where manipulation of the `ID` parameter allows for remote SQL injection. SQL injection is a technique where an attacker inserts malicious SQL code into a query, potentially allowing them to read, modify, or delete data from the database.
**Recommendations**
Update Real State Services to a version newer than 1.0.
As a temporary mitigation, restrict access to the `/single-list sale.php?action=add` endpoint or avoid using the `ID` parameter until a patch is applied.