CVE-2025-9594: itsourcecode Apartment Management System complain_info.php sql injection
A vulnerability has been found in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /report/complaininfo.php. The manipulation of the argument vid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9594?
CVE-2025-9594 is rated as a high severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-9594?
To fix CVE-2025-9594, sanitize and validate all user inputs, particularly the 'vid' argument in the report/complain_info.php file.
Can CVE-2025-9594 be exploited remotely?
Yes, CVE-2025-9594 can be exploited remotely, making it critical for users to address it promptly.
What type of vulnerability is CVE-2025-9594?
CVE-2025-9594 is an SQL injection vulnerability that arises from improper handling of user input.
What software is affected by CVE-2025-9594?
CVE-2025-9594 affects itsourcecode Apartment Management System version 1.0.