CVE Vulnerabilities

CVE-2025-9848

Execution After Redirect (EAR)

Published: Sep 03, 2025 | Modified: Sep 10, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such manipulation leads to execution after redirect. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

Weakness

The web application sends a redirect to another location, but instead of exiting, it executes additional code.

Affected Software

NameVendorStart VersionEnd Version
Real_estate_management_systemScriptandtools1.0 (including)1.0 (including)

References