PT-2026-51200 · Montodel · House-Rental-Management
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Montodel House-Rental-Management versions prior to 90010017b81265eb1ef3810268909f7719a33863
Description
A remote SQL injection exists in the '/index.php?page=houses' endpoint. The issue occurs due to the improper manipulation of the
ID argument, allowing an attacker to execute arbitrary SQL commands.Recommendations
Update to a version later than 90010017b81265eb1ef3810268909f7719a33863.
As a temporary workaround, restrict access to the '/index.php?page=houses' endpoint or avoid using the
ID parameter until the system is updated.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
House-Rental-Management