PT-2026-31728 · Unknown · Os Property Real Estate

Cracker

·

Published

2026-04-09

·

Updated

2026-04-09

·

CVE-2023-54361

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions iProperty Real Estate versions 4.1.1
Description The software contains a reflected cross-site scripting issue. Attackers can inject malicious scripts by manipulating the filter keyword parameter. Specifically, attackers can craft URLs containing JavaScript payloads in the filter keyword GET parameter of the /all-properties-with-map API endpoint to execute arbitrary code in victim browsers and potentially steal session tokens or credentials.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the filter keyword parameter before using it in the /all-properties-with-map endpoint.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-54361

Affected Products

Os Property Real Estate