CVE-2025-9508: itsourcecode Apartment Management System rented_info.php sql injection
Published Aug 27, 2025
·Updated
A vulnerability was detected in itsourcecode Apartment Management System 1.0. The impacted element is an unknown function of the file /report/rentedinfo.php. The manipulation of the argument rsid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
2 affected components
itsourcecode Apartment Management System
Admerc Apartment Management System=1.0
Event History
Aug 27, 2025
CVE Published
via MITRE·04:32 AM
Data Sourced
via MITRE·04:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Feb 27, 57989
Event
via FIRST·10:44 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-9508?
CVE-2025-9508 is considered a high-severity vulnerability due to the potential for SQL injection.
2
How do I fix CVE-2025-9508?
To fix CVE-2025-9508, validate and sanitize user inputs in the rsid argument before processing them.
3
What software is affected by CVE-2025-9508?
CVE-2025-9508 affects the itsourcecode Apartment Management System version 1.0.
4
Can CVE-2025-9508 be exploited remotely?
Yes, CVE-2025-9508 can be exploited remotely through the vulnerable SQL injection point.
5
What kind of attacks can be performed using CVE-2025-9508?
Attackers can execute arbitrary SQL queries on the database due to CVE-2025-9508.