Vulnerability Description
A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function delete_house of the file /admin_class.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mayurik | Best House Rental Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/Cashbeebee/CVE/issues/2ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/?ctiid.331499Permissions RequiredVDB Entry
- https://vuldb.com/?id.331499Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.679152Third Party AdvisoryVDB Entry
- https://www.sourcecodester.com/Product
FAQ
What is CVE-2025-12853?
CVE-2025-12853 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function delete_house of the file /admin_class.php. Executing manipulation of the argument ID...
How severe is CVE-2025-12853?
CVE-2025-12853 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-12853?
Check the references section above for vendor advisories and patch information. Affected products include: Mayurik Best House Rental Management System.