Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.Referenceshttps://projectworlds.inhttps://projectworlds.in/wp-content/uploads/2019/06/home-rental.ziphttps://packetstormsecurity.com/files/158811/House-Rental-1.0-SQL-Injection.html