


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in code-projects Real State Services 1.0. This impacts an unknown function of the file /single-list_rent.php. Executing a manipul…
Published:
4 juli 2026 om 22:00:00
Alert date:
5 juli 2026 om 13:01:30
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A SQL injection vulnerability has been identified in code-projects Real State Services 1.0, specifically in the /single-list_rent.php file. The vulnerability is triggered by manipulating the 'ID' argument, allowing an attacker to execute arbitrary SQL queries. The attack can be launched remotely without requiring physical access to the target system. A public exploit has already been disclosed, increasing the risk of active exploitation. The affected product is a real estate web application built on PHP. The vulnerability has been assigned CVE-2026-14745 and is tracked on multiple security databases including NVD and VulDB. No patch or mitigation details are mentioned in the article. The public availability of the exploit makes this a high-priority issue for users running this software.
Technical details
Mitigation steps:
Affected products:
code-projects Real State Services 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14745
https://code-projects.org/
https://github.com/6Justdododo6/CVE/issues/24
https://vuldb.com/cve/CVE-2026-14745
https://vuldb.com/submit/849265
https://vuldb.com/vuln/376331
https://vuldb.com/vuln/376331/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
