CVE-2025-2419
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 17, 2025
Updated: Apr 7, 2025
CWE ID 400
Summary
CVE-2025-2419 is a critical vulnerability affecting the Real Estate Property Management System 1.0. An unknown function in the file /InsertFeedback.php contains a SQL injection weakness, which can be exploited by manipulating the arguments txtName, txtEmail, txtMobile, or txtFeedback. This vulnerability allows remote attackers to launch SQL injection attacks, potentially compromising sensitive data or gaining unauthorized access to the system. Public disclosure of the exploit increases the risk of widespread exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.