CVE-2026-78244: itsourcecode Real Estate Management System search.php sql injection
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/deliverytype/searchprice/propertytype results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be initiated remotely and requires no privileges or user interaction. An attacker can manipulate the search, delivery_type, search_price, or property_type arguments handled by search.php.
Is public exploit code available?
Yes. The available data states that the exploit is public and may be used, which increases the likelihood of opportunistic exploitation.
What security impact could successful exploitation have?
The supplied severity vector indicates low impact to confidentiality, integrity, and availability. The issue is rated high with a 7.3 severity score.