CVE-2025-1197: code-projects Real Estate Property Management System load_user-profile.php sql injection
A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /parse/loaduser-profile.php. The manipulation of the argument userhash leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1197?
CVE-2025-1197 is classified as a critical security vulnerability.
How does CVE-2025-1197 affect the Real Estate Property Management System?
CVE-2025-1197 affects an unknown functionality of the file /_parse/load_user-profile.php, allowing SQL injection through the userhash argument.
How do I fix CVE-2025-1197?
To fix CVE-2025-1197, ensure that input validation and parameterized queries are implemented to prevent SQL injection.
What software versions are affected by CVE-2025-1197?
CVE-2025-1197 affects version 1.0 of the code-projects Real Estate Property Management System.
What is the potential impact of exploiting CVE-2025-1197?
Exploiting CVE-2025-1197 could lead to unauthorized access to the database and manipulation of sensitive data.