CVE-2025-9848
A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such manipulation leads to execution after redirect. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.61%
- CWE
- CWE-698, CWE-705
- Published
- 2025-09-03
- Last modified
- 2026-03-12
Affected products
- ScriptAndTools Real Estate Management System
Weakness type
Related vulnerabilities
- CVE-2026-16323 — Authentication Bypass via Execution After Redirect in FuyaSoft's Architect Panel Web Management Panel
- CVE-2026-61407 — Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient...
- CVE-2026-58455 — Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
- CVE-2026-10271 — a4m4 Student-Management-System Admin Endpoint admin redirect
- CVE-2026-2699 — EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)
- CVE-2026-3264 — go2ismail Free-CRM Administrative redirect
- CVE-2026-3262 — go2ismail Asp.Net-Core-Inventory-Order-Management-System Administrative redirect
- CVE-2025-8350 — Authentication Bypass with Redirect in BiEticaret Software's BiEticaret CMS