← Back to overview

A SQL injection vulnerability was identified in itsourcecode Real Estate Management System version 1.0. The flaw exists in the file search.php, where manipulation of arguments including search, delivery_type, search_price, and property_type can trigger SQL injection. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit is already available, increasing the risk of active exploitation. The issue affects an unknown portion of the application's functionality. Attackers could potentially extract, modify, or delete database contents through this vector. The vulnerability has been catalogued in NVD, VulDB, and referenced in a GitHub issue. Organizations using this system should apply patches or mitigations immediately given the public exploit availability.

Affected products

  • itsourcecode Real Estate Management System 1.0

Related CVE's

  • CVE-2026-78244

Categories

  • Database & Storage
  • Web Technologies