CVE-2025-9592: itsourcecode Apartment Management System bill_info.php sql injection
A vulnerability was detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/billinfo.php. Performing manipulation of the argument vid results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9592?
CVE-2025-9592 is a critical SQL injection vulnerability that can lead to unauthorized access and exploitation.
How do I fix CVE-2025-9592?
To fix CVE-2025-9592, sanitize and validate all user inputs, especially the 'vid' parameter in the /report/bill_info.php file.
What software is affected by CVE-2025-9592?
CVE-2025-9592 affects itsourcecode Apartment Management System version 1.0.
Can CVE-2025-9592 be exploited remotely?
Yes, CVE-2025-9592 allows for remote exploitation through SQL injection.
What type of attack is CVE-2025-9592 associated with?
CVE-2025-9592 is associated with SQL injection attacks that manipulate server queries to access restricted data.