vendor:
Real Estate Management System
by:
Diyar Saadi
6.1
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Real Estate Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:codeastro:real_estate_management_system:1.0
Platforms Tested: Windows 11 + XAMPP 8.0.30
2024
Real Estate Management System v1.0 – Remote Code Execution via File Upload
The vulnerability in Real Estate Management System v1.0 allows an attacker to execute command injection payloads and upload malicious files to the web server.
Mitigation:
To mitigate this vulnerability, ensure that file uploads are properly validated and sanitized. Additionally, limit the types of files that can be uploaded and validate file extensions.