


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipu…
Published:
4 juli 2026 om 22:00:00
Alert date:
5 juli 2026 om 13:01:30
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Zero-Day Vulnerabilities
A SQL injection vulnerability has been identified in code-projects Real State Services 1.0, specifically in the file /addprojectrent.php. The vulnerability is triggered by manipulating the 'amen' argument, allowing an attacker to perform SQL injection attacks. The attack can be initiated remotely without requiring physical access to the system. A public exploit has already been disclosed, increasing the risk of active exploitation. The affected function within the file is currently unspecified. This vulnerability poses a significant risk to any deployment of the affected software version. Users of code-projects Real State Services 1.0 are advised to apply patches or mitigations as soon as they become available.
Technical details
Mitigation steps:
Affected products:
code-projects Real State Services 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14746
https://code-projects.org/
https://github.com/6Justdododo6/CVE/issues/25
https://vuldb.com/cve/CVE-2026-14746
https://vuldb.com/submit/849284
https://vuldb.com/vuln/376332
https://vuldb.com/vuln/376332/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
