AI description
CVE-2025-5128 is a vulnerability found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Specifically, it affects an unknown function within the Admin Login Panel component, located in the /admin/ file. The vulnerability stems from the manipulation of the "Password" argument, which leads to an SQL injection. This allows for remote exploitation, and a public exploit is available. The vendor was notified but did not respond.
- Description
- A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected is an unknown function of the file /admin/ of the component Admin Login Panel. The manipulation of the argument Password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Source
- cna@vuldb.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 6.9
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Secondary
- Base score
- 7.3
- Impact score
- 3.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity
- HIGH
CVSS 2.0
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
- cna@vuldb.com
- CWE-74
- Hype score
- Not currently trending
🚨CVE-2025-5128: SQL Injection Vulnerability in ScriptAndTools Real-Estate Admin panel bypass Credit: https://t.co/xu46l40TY3 Advisory: https://t.co/VweLfm6vNA https://t.co/pLh7TZ3d5u
@DarkWebInformer
31 May 2025
8149 Impressions
26 Retweets
184 Likes
90 Bookmarks
0 Replies
0 Quotes
CVE-2025-5128 (CVSS:6.9, HIGH) is Awaiting Analysis. A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected ..https://t.co/e4yKSr6ptr #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
29 May 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-5128 A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected is an unknown function of the file /admin/ of th… https://t.co/yfoF3SopXZ
@CVEnew
24 May 2025
846 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes