SQL Injection Vulnerability in Code-Projects Real State Services by Code-Projects
CVE-2026-13559
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 29 June 2026
Badges
What is CVE-2026-13559?
A vulnerability has been detected in the Code-Projects Real State Services, specifically in the function within the file /single-list_sale.php when the action parameter is set to 'add'. By manipulating the argument ID, an attacker can execute an SQL injection, potentially exposing sensitive data. This flaw allows remote exploitation, making it essential for users of Real State Services 1.0 to implement necessary security measures to safeguard their applications and databases. Researchers have disclosed the exploit details publicly, prompting immediate attention to this security risk.
Affected Version(s)
Real State Services 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
