PT-2022-7997 · Itech · Itech Real Estate Script

Kaan Kamis

·

Published

2022-07-16

·

Updated

2022-07-21

·

CVE-2017-20130

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Itech Real Estate Script version 3.12
Description A critical issue affects an unknown functionality of the file /real-estate-script/search property.php. The manipulation of the property for argument leads to SQL injection. The attack can be launched remotely.
Recommendations For Itech Real Estate Script version 3.12, consider restricting access to the /real-estate-script/search property.php file until a patch is available. As a temporary workaround, avoid using the property for argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20130

Affected Products

Itech Real Estate Script