CVE-2025-9509: itsourcecode Apartment Management System fair_info_all.php sql injection
A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/fairinfoall.php. Performing manipulation of the argument fid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9509?
CVE-2025-9509 has a high severity rating due to its potential for remote SQL injection attacks.
How can I fix CVE-2025-9509?
To fix CVE-2025-9509, validate and sanitize user inputs for the fid parameter in the /report/fair_info_all.php file to prevent SQL injection.
What systems are affected by CVE-2025-9509?
CVE-2025-9509 affects version 1.0 of the itsourcecode Apartment Management System.
Can CVE-2025-9509 be exploited remotely?
Yes, CVE-2025-9509 can be exploited remotely, allowing attackers to perform SQL injection attacks.
What kind of attack does CVE-2025-9509 enable?
CVE-2025-9509 enables SQL injection attacks through manipulation of the fid parameter.