CVE-2025-9418: itsourcecode Apartment Management System addowner.php sql injection
A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /owner/addowner.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9418?
CVE-2025-9418 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
How does CVE-2025-9418 affect the Apartment Management System?
CVE-2025-9418 affects the 'addowner.php' file, allowing attackers to manipulate the ID parameter and execute SQL injection.
How can I fix CVE-2025-9418?
Fixing CVE-2025-9418 involves sanitizing and validating user inputs to prevent SQL injection in the Apartment Management System.
Who is affected by CVE-2025-9418?
Any users of itsourcecode Apartment Management System version 1.0 are vulnerable to CVE-2025-9418.
Can CVE-2025-9418 be exploited remotely?
Yes, CVE-2025-9418 can be exploited remotely, making it a significant security risk.