Executive brief
A security vulnerability exists in code-projects Real State Services 1.0, a web application used for managing property rentals. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive information or the disruption of the service. This attack can be carried out remotely without requiring any user credentials or special access.
Technical details
A SQL injection vulnerability exists in the 'normalHomeRent.php' file of code-projects Real State Services 1.0. The root cause is the improper neutralization of the 'loc' POST parameter, which is used directly in SQL queries without adequate sanitization or the use of prepared statements. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to perform boolean-based blind, error-based, time-based blind, or UNION-based SQL injection attacks. Successful exploitation allows for unauthorized database access, data exfiltration, and potential tampering with records. Public exploit code (PoC) using sqlmap has been released.
Affected products
- code-projects Real State Services 1.0
Timeline
- 2026-06-05: disclosed: Vulnerability reported on GitHub by user 6Justdododo6
- 2026-07-05: advisory: NVD/VulDB advisory published