CVE-2025-9940: CodeAstro Real Estate Management System feature.php cross site scripting
A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /feature.php. Performing manipulation of the argument msg results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9940?
The severity of CVE-2025-9940 is considered high, as it allows for remote cross-site scripting attacks.
How do I fix CVE-2025-9940?
To fix CVE-2025-9940, update the CodeAstro Real Estate Management System to the latest patched version that addresses this vulnerability.
Which versions are affected by CVE-2025-9940?
CVE-2025-9940 affects CodeAstro Real Estate Management System 1.0 and possibly earlier versions.
What types of attacks can be executed using CVE-2025-9940?
CVE-2025-9940 can be exploited to perform cross-site scripting (XSS) attacks by manipulating the argument msg.
Is CVE-2025-9940 a local or remote vulnerability?
CVE-2025-9940 is a remote vulnerability, allowing attackers to exploit it from a distance without prior access.