House Rental System是一个房屋租赁管理系统,可实现房源信息的添加修改删除,能够进行下单预定。 House Rental System存在SQL注入漏洞,该漏洞源于组件 POST 请求处理程序的文件 search-property.php 的未知功能,参数search_property的操作导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| unspecified | House Rental System | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-4274 | 6.3 MEDIUM | House Rental System view-property.php sql injection |
| CVE-2022-4276 | 6.3 MEDIUM | House Rental System POST Request tenant-engine.php unrestricted upload |
No comments yet