CVE-2025-9593: itsourcecode Apartment Management System unit_status_info.php sql injection
A flaw has been found in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/unitstatusinfo.php. Executing manipulation of the argument usid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9593?
CVE-2025-9593 is classified as a high severity vulnerability due to its potential for remote SQL injection.
How can I mitigate CVE-2025-9593?
To mitigate CVE-2025-9593, sanitize and validate all user inputs, especially the 'usid' parameter in the /report/unit_status_info.php file.
Is CVE-2025-9593 widely exploitable?
Yes, CVE-2025-9593 can be exploited remotely, making it a significant threat to systems using the affected version of the Apartment Management System.
What are the potential impacts of CVE-2025-9593?
Exploiting CVE-2025-9593 could allow attackers to execute arbitrary SQL queries, potentially leading to data leakage or database manipulation.
Which version of the Apartment Management System is affected by CVE-2025-9593?
CVE-2025-9593 affects version 1.0 of the itsourcecode Apartment Management System.