CVE-2025-9598: itsourcecode Apartment Management System year_setup.php sql injection
A security flaw has been discovered in itsourcecode Apartment Management System 1.0. Affected is an unknown function of the file /setting/yearsetup.php. Performing manipulation of the argument txtXYear results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9598?
CVE-2025-9598 is classified as a high severity vulnerability due to its potential for remote exploitation via SQL injection.
How do I fix CVE-2025-9598?
To mitigate CVE-2025-9598, ensure input validation and parameterized queries are implemented in the /setting/year_setup.php file.
What systems are affected by CVE-2025-9598?
CVE-2025-9598 affects the itsourcecode Apartment Management System version 1.0.
Is CVE-2025-9598 exploitable remotely?
Yes, CVE-2025-9598 can be exploited remotely, making it critical to address immediately.
What type of vulnerability is CVE-2025-9598?
CVE-2025-9598 is a SQL injection vulnerability that allows manipulation of database queries.