PT-2022-26540 · Unknown · House Rental System

Ace

·

Published

2022-12-03

·

Updated

2022-12-06

·

CVE-2022-4275

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions House Rental System (affected versions not specified)
Description A critical vulnerability has been found in the House Rental System, affecting an unknown functionality of the file search-property.php of the component POST Request Handler. The manipulation of the search property argument leads to sql injection. The attack can be launched remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the vulnerable search-property.php file or disabling the manipulation of the search property argument in the POST Request Handler to minimize the risk of exploitation.

Exploit

Improper Neutralization

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-4275

Affected Products

House Rental System