PT-2025-26296 · Scriptandtools · Scriptandtools Real Estate Management System

Maloyroyorko

·

Published

2025-06-20

·

Updated

2025-07-18

·

CVE-2025-6329

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ScriptAndTools Real Estate Management System version 1.0
Description: A critical issue affects the unknown processing of the file userdelete.php of the component User Delete Handler in ScriptAndTools Real Estate Management System. The manipulation of the argument ID leads to authorization bypass. The attack may be initiated remotely.
Recommendations: For ScriptAndTools Real Estate Management System version 1.0, consider disabling the userdelete.php file or restricting access to the User Delete Handler component until a patch is available. Avoid using the ID argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-6329

Affected Products

Scriptandtools Real Estate Management System