PT-2025-35651 · Unknown · Scriptandtools Real Estate Management System

Maloyroyorko

·

Published

2025-09-03

·

Updated

2025-09-03

·

CVE-2025-9847

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ScriptAndTools Real Estate Management System version 1.0
Description A weakness has been identified in an unknown function of the register.php file, allowing for unrestricted file upload through manipulation of the uimage argument. Remote exploitation is possible, and the exploit has been made publicly available.
Recommendations As a temporary workaround, consider restricting access to the register.php file to minimize the risk of exploitation. Avoid uploading any files through the uimage parameter until a fix is available.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-9847

Affected Products

Scriptandtools Real Estate Management System