Junglewise Threat Intelligence

CVE-2026-14747: code-projects Real State Services SQL injection in addprojectsale.php

CVE-2026-14747 · Severity: high · CVSS 7.3 · Published 2026-07-05

Technologies: Code-Projects Real State Services. Vendors: Code-Projects.

Executive brief

Real State Services is a web application used for managing real estate listings and sales. A security flaw in the application allows remote attackers to interfere with the underlying database without needing to log in. This could lead to the theft of sensitive property data, unauthorized modification of listings, or disruption of the service.

Technical details

A SQL injection vulnerability exists in code-projects Real State Services 1.0 within the 'addprojectsale.php' file. The root cause is the improper neutralization of special elements in the 'amen' POST parameter, which is used directly in SQL queries without validation or prepared statements. A remote, unauthenticated attacker can exploit this by sending crafted HTTP POST requests to perform error-based or time-based blind SQL injection. Successful exploitation allows for unauthorized database access, data exfiltration, and potential administrative control over the application's backend. No patch is currently documented; remediation should involve implementing prepared statements with parameterized queries.

Affected products

  • code-projects Real State Services 1.0

Timeline

  • 2026-06-05: disclosed: Initial discovery and report on GitHub by XuYue
  • 2026-07-05: advisory: NVD and VulDB publication

References

Related threats