CVE-2025-9507: itsourcecode Apartment Management System visitor_info.php sql injection
A weakness has been identified in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/visitorinfo.php. Executing manipulation of the argument vid can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9507?
CVE-2025-9507 is considered a critical vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-9507?
To fix CVE-2025-9507, ensure proper validation and sanitization of the 'vid' parameter in the /report/visitor_info.php file.
Who is affected by CVE-2025-9507?
CVE-2025-9507 affects users of itsourcecode Apartment Management System version 1.0.
What can attackers do with CVE-2025-9507?
Attackers can exploit CVE-2025-9507 to perform SQL injection attacks, potentially compromising the database.
Is CVE-2025-9507 remotely exploitable?
Yes, CVE-2025-9507 can be exploited remotely, allowing attackers to manipulate the 'vid' argument without local access.