Impact
A flaw in the normalHomeRent.php file of code‑projects Real State Services 1.0 lets an attacker modify the loc parameter, causing arbitrary SQL statements to be executed against the application database. The vulnerability is identified as CWE‑89 and CWE‑74. Based on the description, it is inferred that an attacker can read or alter sensitive data stored in the database, thereby compromising confidentiality and integrity of the application’s information.
Affected Systems
The vulnerability is present in code‑projects Real State Services version 1.0. No other versions or products have been identified as affected.
Risk and Exploitability
The flaw carries a CVSS score of 6.9, indicating moderate severity. The EPSS score is less than 1%, indicating a low likelihood of exploitation in the wild. The exploit is publicly available, yet the vulnerability is not listed in the CISA KEV catalog, meaning it is not a known high‑profile target. Attackers can trigger the vulnerability remotely by crafting a request; successful exploitation allows them to execute arbitrary SQL commands to read or modify data in the underlying database.
OpenCVE Enrichment