Impact
Netartmedia Real Estate Portal 5.0 contains a classic SQL injection flaw (CWE-89). An unauthenticated attacker can send a crafted POST request to index.php and inject SQL code through the page parameter. If successful, the attacker can bypass authentication controls, read sensitive data from the database, or alter critical data such as property listings or client information. The vulnerability allows direct manipulation of database queries, leading to disclosure, modification, or loss of integrity of stored data.
Affected Systems
The flaw affects the Netartmedia Real Estate Portal product, version 5.0. No other versions are mentioned, and the CPE listing confirms 5.0 as the affected release.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity vulnerability, and the EPSS score of less than 1% indicates low but not negligible exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, yet the unauthenticated nature and ease of sending a POST request make it relatively easy to exploit in practice. An attacker would need network access to the web server, but no special privileges or prior compromise are required.
OpenCVE Enrichment