CVE-2025-9417: itsourcecode Apartment Management System addemployee.php sql injection
A weakness has been identified in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /employee/addemployee.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9417?
CVE-2025-9417 has been identified as a critical vulnerability due to its ability to facilitate SQL injection attacks.
How do I fix CVE-2025-9417?
To fix CVE-2025-9417, sanitize and validate input parameters used in the /employee/addemployee.php file to prevent SQL injection.
What systems are affected by CVE-2025-9417?
CVE-2025-9417 affects the itsourcecode Apartment Management System version 1.0.
Can CVE-2025-9417 be exploited remotely?
Yes, CVE-2025-9417 can be exploited remotely, allowing attackers to execute SQL injection attacks from an external network.
What are the potential consequences of CVE-2025-9417?
The consequences of CVE-2025-9417 include unauthorized access to the database, data loss, and manipulation of sensitive information.