PT-2025-19840 · Unknown · Real Estate Management System

Published

2025-05-06

·

Updated

2025-05-06

·

CVE-2023-33770

CVSS v3.1

5.1

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Real Estate Management System version 1.0
Description The issue is related to a SQL injection vulnerability. It can be exploited via the message parameter at the "/contact.php" API endpoint.
Recommendations For Real Estate Management System version 1.0, consider restricting access to the "/contact.php" endpoint until a patch is available. As a temporary workaround, avoid using the message parameter in the affected API endpoint to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-33770

Affected Products

Real Estate Management System