vendor:
Real Estate Management System
by:
Diyar Saadi
6.1
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Real Estate Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:codeastro:real_estate_management_system:1.0
Platforms Tested: Windows 11, XAMPP 8.0.30
2024
Real Estate Management System v1.0 – Remote Code Execution via File Upload
The vulnerability in Real Estate Management System v1.0 allows an attacker to upload malicious files and execute command injection payloads on the web server.
Mitigation:
To mitigate this vulnerability, ensure that file uploads are properly validated and restrict the file types that can be uploaded. Additionally, sanitize user inputs to prevent command injection.