Junglewise Threat Intelligence

CVE-2026-78244: itsourcecode Real Estate Management System SQL injection in search.php

CVE-2026-78244 · Severity: high · CVSS 7.3 · Published 2026-08-24

Vendors: Itsourcecode.

Executive brief

itsourcecode Real Estate Management System is a web application for managing property listings and real estate transactions. An attacker can exploit a SQL injection vulnerability in the search functionality to extract, modify, or delete the entire database containing property listings, agent information, and user data without requiring any authentication.

Technical details

The search.php endpoint processes four POST parameters (search, delivery_type, search_price, property_type) via direct string concatenation into SQL queries without sanitization, escaping, or prepared statements. The vulnerability is CWE-89 (improper neutralization of special elements used in an SQL command). No authentication is required; the endpoint is publicly accessible. An attacker can execute blind SQL injection or UNION-based extraction attacks to compromise the entire database, which runs with root MySQL privileges. Remediation requires implementing prepared statements with parameterized queries.

Affected products

  • itsourcecode Real Estate Management System 1.0

Timeline

  • 2026-07-11: disclosed
  • 2026-08-24: advisory

References