Description
A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/complaint.php. The manipulation of the argument Name results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-01-06: | Advisory disclosed |
| 2026-01-06: | VulDB entry created |
| 2026-01-17: | VulDB entry last update |
Credits
Li Feng (VulDB User)
References
github.com/Pick-program/CVE/issues/4
vuldb.com/?id.339685 (VDB-339685 | projectworlds House Rental and Property Listing complaint.php cross site scripting)
vuldb.com/?ctiid.339685 (VDB-339685 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.732369 (Submit #732369 | projectworlds.com House rental And Property Listing 1.0 Cross Site Scripting)
vuldb.com/?submit.736161 (Submit #736161 | projectworlds.com House rental And Property Listing Project V1.0 XSS Injection (Duplicate))
github.com/Pick-program/CVE/issues/4