Impact
The addprojectsale.php script in code‑projects Real State Services 1.0 contains an input‑validation flaw that permits an attacker to manipulate the amen parameter and inject arbitrary SQL code into the database query. This flaw allows execution of malicious SQL statements, potentially enabling read, write, or delete operations on the backend database if the application’s database account has sufficient privileges. The description acknowledges that the attack can be launched remotely but does not specify authentication requirements or exact data compromise scenarios.
Affected Systems
Only version 1.0 of code‑projects Real State Services is reported as vulnerable, affecting the /addprojectsale.php endpoint. No other versions or modules are identified in the supplied data.
Risk and Exploitability
The CVSS score of 6.9 signifies medium severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack can be launched remotely by sending crafted requests to the amen parameter. It is inferred that the vulnerability may be exploitable without authentication, but the description does not explicitly confirm this; therefore, this inference may not be accurate.
OpenCVE Enrichment