CVE-2025-9939: CodeAstro Real Estate Management System propertyview.php cross site scripting
A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /propertyview.php. Such manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9939?
CVE-2025-9939 is classified as a high-severity vulnerability due to its ability to enable remote code execution via cross-site scripting.
How do I fix CVE-2025-9939?
To fix CVE-2025-9939, you should sanitize user inputs in the /propertyview.php file to prevent XSS attacks.
What type of vulnerability is CVE-2025-9939?
CVE-2025-9939 is a Cross-Site Scripting (XSS) vulnerability that affects the CodeAstro Real Estate Management System.
Which versions are affected by CVE-2025-9939?
CVE-2025-9939 impacts CodeAstro Real Estate Management System version 1.0.
Can CVE-2025-9939 be exploited remotely?
Yes, CVE-2025-9939 can be exploited remotely, allowing attackers to inject malicious scripts through the affected function.