The Rental Module Project maintains a narrowly scoped property-rental application component, with a durable vulnerability signal centered on access-control and file-handling weaknesses. The observed exposure recurs through authorization bypasses tied to user-controlled keys and unrestricted file uploads accepting dangerous types, reflecting common risks in web-facing administrative and data-entry contexts. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rental Module Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2712CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malici | May 20, 2023 | 9.8 | 32 | NO | NO |
CVE-2023-2713CRITICAL Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authenti | May 20, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rental Module Project.
Media articles that mention a CVE ID that affects a product developed by Rental Module Project — matched by CVE ID, not by vendor name.