We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file userdelete.php of the component User Delete Handler. The manipulation of the argument ID leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Eine Schwachstelle wurde in ScriptAndTools Real Estate Management System 1.0 ausgemacht. Sie wurde als kritisch eingestuft. Davon betroffen ist unbekannter Code der Datei userdelete.php der Komponente User Delete Handler. Dank Manipulation des Arguments ID mit unbekannten Daten kann eine authorization bypass-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
2025-06-19: | Advisory disclosed |
2025-06-19: | Exploit disclosed |
2025-06-19: | VulDB entry created |
2025-06-19: | VulDB entry last update |
Maloy Roy Orko
MaloyRoyOrko (VulDB User)
MaloyRoyOrko (VulDB User)
vuldb.com/?id.313325 (VDB-313325 | ScriptAndTools Real Estate Management System User Delete userdelete.php authorization)
vuldb.com/?ctiid.313325 (VDB-313325 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.596472 (Submit #596472 | Script And Tools Real-Estate-Management-System 1.0 Insecure Direct Object Reference (IDOR))
www.websecurityinsights.my.id/...real-estate-management.html
Support options