CVE-2025-14530
SourceCodester Real Estate Property Listing App property.php unrestricted upload
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.1EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin/property.php. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
SourceCodester · Real Estate Property Listing AppWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →