Skip to content

CVE-2023-3806 | House Rental and Property Listing System

A vulnerability, which was classified as critical, was found in SourceCodester House Rental and Property Listing System 1.0. Affected is an unknown function of the file btn_functions.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235074 is the identifier assigned to this vulnerability..This CVE has a CVSS3.1 score of 6.3 and a Base Severity of MEDIUM.

InfoDetails
CVE IDCVE-2023-3806
CVE StatePUBLISHED
BaseScore6.3
BaseSeverityMEDIUM
VectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
VersionNA

References for CVE-2023-3806 :
https://vuldb.com/?id.235074
https://vuldb.com/?ctiid.235074
https://github.com/GZRsecurity/Cve-System/blob/main/House%20Rental%20and%20Property%20Listing%20System%20register.php%20has%20%20File%20Upload(RCE)%20Vulnerability.pdf

Metric TypeMetric Score
AttackVector(AV)NA
AttackComplexity(AC)NA
PrivilegesRequired(PR)NA
UserInteraction(UI)NA
Scope(S)NA
Confidentiality(C)NA
Availability(A)NA
Integrity(I)NA