Impact
An unknown function within normalHomeSale.php in code‑projects Real State Services allows an attacker to manipulate the loc argument and inject arbitrary SQL statements. The flaw is a classic SQL injection, identified as CWE‑74 and CWE‑89. Successful exploitation could let an attacker read, modify, or delete the application’s database contents, compromising confidentiality, integrity, and availability of real‑estate records.
Affected Systems
code‑projects Real State Services version 1.0 is affected; any deployment of this release exposes the flaw. No other versions have been identified as impacted in the current data.
Risk and Exploitability
The CVSS score of 6.9 denotes moderate severity, while the EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, indicating a low current exploitation probability. Nevertheless, the defect can be abused remotely through the loc parameter, and publicly available proof‑of‑concept code exists. An attacker requires no authentication, so the actual impact depends on the environment, but the capacity to alter or exfiltrate database content remains significant.
OpenCVE Enrichment