TROYANOSYVIRUS
Voltar para CVEs

CVE-2025-9848

HIGH
7.3

Descricao

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such manipulation leads to execution after redirect. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

Detalhes CVE

Pontuacao CVSS v3.17.3
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado9/3/2025
Ultima modificacao9/10/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

scriptandtools:real_estate_management_system

Fraquezas (CWE)

CWE-698CWE-705

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.