CVE-2026-14747: code-projects Real State Services addprojectsale.php sql injection
A vulnerability was detected in code-projects Real State Services 1.0. Affected by this vulnerability is an unknown functionality of the file /addprojectsale.php. The manipulation of the argument amen results in sql injection. The attack can be launched remotely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14747?
CVE-2026-14747 has a high severity rating of 7.3.
How does CVE-2026-14747 affect my system?
CVE-2026-14747 allows for SQL injection through the /addprojectsale.php file in the Code-projects Real State Services application.
What can an attacker do with CVE-2026-14747?
An attacker can execute remote SQL injection attacks by manipulating the 'amen' argument in the affected file.
How do I fix CVE-2026-14747?
To fix CVE-2026-14747, you should sanitize and validate all user inputs in the /addprojectsale.php file to prevent SQL injection.
Is my version vulnerable to CVE-2026-14747?
Yes, Code-projects Real State Services version 1.0 is vulnerable to CVE-2026-14747.