CVE-2025-1196: code-projects Real Estate Property Management System search.php cross site scripting
A vulnerability, which was classified as problematic, was found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /search.php. The manipulation of the argument PropertyName/StateName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1196?
CVE-2025-1196 is classified as problematic due to its potential for cross-site scripting vulnerabilities.
How do I fix CVE-2025-1196?
To fix CVE-2025-1196, sanitize and validate the input for the PropertyName argument in the /search.php file.
What systems are affected by CVE-2025-1196?
CVE-2025-1196 affects the Real Estate Property Management System version 1.0 developed by code-projects.
What type of attack can CVE-2025-1196 facilitate?
CVE-2025-1196 can facilitate cross-site scripting attacks, allowing an attacker to inject malicious scripts into web pages.
Is user data at risk due to CVE-2025-1196?
Yes, user data can be at risk due to CVE-2025-1196 if an attacker successfully executes a cross-site scripting attack.