CVE-2025-9468: itsourcecode Apartment Management System add_bill.php sql injection
A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /bill/addbill.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9468?
The severity of CVE-2025-9468 is classified as critical due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2025-9468?
To fix CVE-2025-9468, sanitize and validate all user inputs, specifically the ID parameter in the /bill/add_bill.php file.
Who is affected by CVE-2025-9468?
Any installations of itsourcecode Apartment Management System version 1.0 are affected by CVE-2025-9468.
What type of vulnerability is CVE-2025-9468?
CVE-2025-9468 is an SQL injection vulnerability that allows remote attackers to manipulate database queries.
What could happen if CVE-2025-9468 is exploited?
Exploitation of CVE-2025-9468 could lead to unauthorized access to sensitive data or database corruption.