CVE-2025-5581: CodeAstro Real Estate Management System index.php sql injection
Published Jun 4, 2025
·Updated
A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument User leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Codeastro Real Estate Management System
Codeastro Real Estate Management System=1.0
Event History
Jun 4, 2025
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
DescriptionSeverityWeakness
Aug 30, 57482
Event
via FIRST·12:53 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5581?
CVE-2025-5581 has been declared as a critical vulnerability.
2
How does CVE-2025-5581 affect the system?
CVE-2025-5581 allows for SQL injection through manipulation of the User argument in the /admin/index.php file.
3
Can CVE-2025-5581 be exploited remotely?
Yes, CVE-2025-5581 can be exploited remotely by an attacker.
4
What software is affected by CVE-2025-5581?
CVE-2025-5581 affects the CodeAstro Real Estate Management System version 1.0.
5
How can I fix CVE-2025-5581?
To fix CVE-2025-5581, you should sanitize and validate the User input to prevent SQL injection.