A vulnerability, which was classified as problematic, was found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /search.php. The manipulation of the argument PropertyName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
References
Link | Resource |
---|---|
https://code-projects.org/ | Product |
https://github.com/YinshengLu/CVE/blob/main/cve2.pdf | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.295104 | Permissions Required VDB Entry |
https://vuldb.com/?id.295104 | VDB Entry |
https://vuldb.com/?submit.496855 | VDB Entry |
Configurations
History
20 Feb 2025, 20:38
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
References | () https://vuldb.com/?id.295104 - VDB Entry | |
References | () https://github.com/YinshengLu/CVE/blob/main/cve2.pdf - Exploit, Third Party Advisory | |
References | () https://code-projects.org/ - Product | |
References | () https://vuldb.com/?ctiid.295104 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?submit.496855 - VDB Entry | |
First Time |
Fabian real Estate Property Management System
Fabian |
|
CPE | cpe:2.3:a:fabian:real_estate_property_management_system:1.0:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
16 Feb 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary | A vulnerability, which was classified as problematic, was found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /search.php. The manipulation of the argument PropertyName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. |
16 Feb 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
Summary | A vulnerability, which was classified as problematic, was found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /search.php. The manipulation of the argument PropertyName/StateName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. | |
CWE | CWE-79 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
12 Feb 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-12 12:15
Updated : 2025-02-20 20:38
NVD link : CVE-2025-1196
Mitre link : CVE-2025-1196
JSON object : View
Products Affected
fabian
- real_estate_property_management_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')