CVE-2026-0643: projectworlds House Rental and Property Listing Signup register.php unrestricted upload
A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0643?
CVE-2026-0643 is classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2026-0643?
To fix CVE-2026-0643, update the House Rental and Property Listing software to the latest version that addresses this vulnerability.
What is the impact of CVE-2026-0643?
CVE-2026-0643 allows for unrestricted file uploads, which can lead to remote code execution.
Which versions are affected by CVE-2026-0643?
CVE-2026-0643 affects Projectworlds House Rental and Property Listing version 1.0.
Can CVE-2026-0643 be exploited remotely?
Yes, CVE-2026-0643 can be exploited remotely, making it particularly dangerous for web applications.