CVE-2025-9470: itsourcecode Apartment Management System add_m_committee.php sql injection
A flaw has been found in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file /management/addmcommittee.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9470?
CVE-2025-9470 is considered a high severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-9470?
To fix CVE-2025-9470, validate and sanitize user input in the add_m_committee.php file to prevent SQL injection.
Who is affected by CVE-2025-9470?
The vulnerability affects users of itsourcecode Apartment Management System version 1.0.
Can CVE-2025-9470 be exploited remotely?
Yes, CVE-2025-9470 can be exploited remotely due to the nature of the SQL injection vulnerability.
What component of itsourcecode Apartment Management System is vulnerable in CVE-2025-9470?
The vulnerable component is the add_m_committee.php file within the itsourcecode Apartment Management System.