CVE-2025-9644: itsourcecode Apartment Management System bill_setup.php sql injection
A vulnerability was determined in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /setting/billsetup.php. Executing manipulation of the argument txtBillType can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9644?
CVE-2025-9644 is classified as a critical vulnerability due to the potential for SQL injection attacks that can compromise the database.
How do I fix CVE-2025-9644?
To fix CVE-2025-9644, ensure proper validation and sanitization of the txtBillType parameter in the /setting/bill_setup.php file.
What software is affected by CVE-2025-9644?
CVE-2025-9644 affects itsourcecode Apartment Management System version 1.0.
What kind of attack can be executed due to CVE-2025-9644?
CVE-2025-9644 can lead to SQL injection attacks allowing unauthorized access to the database.
Is CVE-2025-9644 easy to exploit?
Yes, CVE-2025-9644 can be easily exploited due to inadequate input validation on the parameter in question.