High severity8.2NVD Advisory· Published Mar 12, 2026· Updated Apr 7, 2026
CVE-2019-25536
CVE-2019-25536
Description
Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can send POST requests to index.php with crafted SQL payloads in the features[] parameter to extract sensitive database information or manipulate database queries.
Affected products
1- cpe:2.3:a:netartmedia:real_estate_portal:4.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/46574nvdVDB EntryExploit
- www.vulncheck.com/advisories/netartmedia-php-real-estate-agency-sql-injection-via-features-parameternvdThird Party Advisory
News mentions
0No linked articles in our index yet.