CVE-2026-10251: falha de média gravidade em itsourcecode Online House Rental System
itsourcecode Online House Rental System ajax.php login sql injection
Publicada em · Atualizada em
33Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 6.9epss 0.3%
probabilidade de exploração
0.3%top 83% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
itsourcecode · Online House Rental SystemPoCs públicas encontradas — 1
cve_referencegithub.com/zhengdexu-bot/zhengdexu/issues/3não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
CVEs relacionadas — itsourcecode Online House Rental System
No mesmo produto, das mais perigosas para as menos.
CVE-2024-5981MEDIUMitsourcecode Online House Rental System manage_user.php sql injectionEPSS 0.5%CVE-2024-6015MEDIUMitsourcecode Online House Rental System manage_user.php sql injectionEPSS 0.5%CVE-2026-10253MEDIUMitsourcecode Online House Rental System manage_payment.php sql injectionEPSS 0.3%CVE-2026-10252MEDIUMitsourcecode Online House Rental System manage_tenant.php sql injectionEPSS 0.3%