Executive brief
A security vulnerability has been identified in Montodel House-Rental-Management, a software system used for managing property rentals. An attacker can exploit the login page to bypass security controls and interact directly with the underlying database. This could lead to unauthorized access to the management system, the theft of sensitive tenant or financial data, or the disruption of rental operations.
Technical details
A SQL injection vulnerability exists in Montodel House-Rental-Management up to version hash 90010017b81265eb1ef3810268909f7719a33863. The root cause is the improper neutralization of special elements in the 'Username' parameter within the /login.php file (often accessed via ajax.php?action=login). A remote, unauthenticated attacker can send specially crafted POST requests containing SQL payloads to manipulate database queries. This can be used to perform time-based blind SQL injection to extract sensitive information, bypass authentication, or modify database records. A public exploit (PoC) is available, and the vendor has not yet released a patch.
Affected products
- Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863
Timeline
- 2026-05-21: disclosed: Initial disclosure on GitHub issues
- 2026-06-21: advisory: CVE published and NVD record created