Impact
The reported weakness exists in the single‑list_rent.php script of code‑projects Real State Services 1.0. Manipulating the URL query parameter ID causes the backend to embed the value directly into an SQL query, allowing an attacker to inject arbitrary SQL code. The flaw is classified as CWE‑89. Successful exploitation permits the attacker to read, modify, or delete data stored in the application’s database, thereby compromising confidentiality, integrity, and potentially availability of the system.
Affected Systems
Any installation of code‑projects Real State Services 1.0 that exposes the single‑list_rent.php endpoint is vulnerable. The weakness is tied to an unspecified function within that file, so any server running that module with a publicly reachable endpoint is at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, and the EPSS score shown as <1% suggests a low current likelihood of exploitation. Publicly available exploit code is noted, and the description states the attack can be launched remotely. No authentication requirement is explicitly documented, so the vulnerability is reachable from the Internet. The issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment