Report: CVE-2019-25536 - Netartmedia PHP Real Estate Agency 4.0 SQL Injection via features parameter
CVE ID :CVE-2019-25536 Published : March 12, 2026, 3:37 p.m. | 23 minutes ago Description :Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can send POST requests to index.php with crafted SQL payloads in the features[] parameter to extract sensitive database information or manipulate database queries. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...