CVE-2025-14900: CodeAstro Real Estate Management System Administrator Endpoint userdelete.php sql injection
A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /admin/userdelete.php of the component Administrator Endpoint. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14900?
CVE-2025-14900 has been classified as a high severity vulnerability due to the potential for SQL injection.
How do I fix CVE-2025-14900?
To fix CVE-2025-14900, validate and sanitize input parameters in the /admin/userdelete.php file to prevent SQL injection.
What component is affected by CVE-2025-14900?
CVE-2025-14900 affects the Administrator Endpoint component of the CodeAstro Real Estate Management System.
Can CVE-2025-14900 be exploited remotely?
Yes, CVE-2025-14900 can potentially be exploited remotely by manipulating the argument ID.
What systems are vulnerable to CVE-2025-14900?
CVE-2025-14900 specifically affects CodeAstro Real Estate Management System version 1.0.