CVE-2026-14744

medium

Description

A security flaw has been discovered in code-projects Real State Services 1.0. This affects an unknown function of the file /normalHomeRent.php. Performing a manipulation of the argument loc results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

References

https://vuldb.com/vuln/376330/cti

https://vuldb.com/vuln/376330

https://vuldb.com/submit/849260

https://vuldb.com/cve/CVE-2026-14744

https://github.com/6Justdododo6/CVE/issues/23

https://code-projects.org/

Details

Source: Mitre, NVD

Published: 2026-07-05

Updated: 2026-07-07

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 7.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Severity: High

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00263