Executive brief
itsourcecode Real Estate Management System is a web application for managing property listings and real estate transactions. An attacker can exploit a SQL injection vulnerability in the search functionality to extract, modify, or delete the entire database containing property listings, agent information, and user data without requiring any authentication.
Technical details
The search.php endpoint processes four POST parameters (search, delivery_type, search_price, property_type) via direct string concatenation into SQL queries without sanitization, escaping, or prepared statements. The vulnerability is CWE-89 (improper neutralization of special elements used in an SQL command). No authentication is required; the endpoint is publicly accessible. An attacker can execute blind SQL injection or UNION-based extraction attacks to compromise the entire database, which runs with root MySQL privileges. Remediation requires implementing prepared statements with parameterized queries.
Affected products
- itsourcecode Real Estate Management System 1.0
Timeline
- 2026-07-11: disclosed
- 2026-08-24: advisory