CVE-2025-5580: CodeAstro Real Estate Management System login.php sql injection
Published Jun 4, 2025
·Updated
A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Codeastro Real Estate Management System
Codeastro Real Estate Management System=1.0
Event History
Jun 4, 2025
CVE Published
via MITRE·08:31 AM
Data Sourced
via MITRE·08:31 AM
DescriptionSeverityWeakness
Aug 30, 57482
Event
via FIRST·08:51 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-5580?
CVE-2025-5580 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-5580?
CVE-2025-5580 is an SQL injection vulnerability affecting the login functionality.
3
How does CVE-2025-5580 affect the CodeAstro Real Estate Management System?
CVE-2025-5580 allows remote attackers to manipulate the email parameter leading to SQL injection.
4
How do I fix CVE-2025-5580 in my CodeAstro Real Estate Management System?
To fix CVE-2025-5580, validate and sanitize user input for the email argument in the login.php file.
5
Is CVE-2025-5580 exploitable remotely?
Yes, CVE-2025-5580 is exploitable remotely which increases its risk level.