CVE-2025-9792: itsourcecode Apartment Management System e_all_info.php sql injection
A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /edashboard/eallinfo.php. Such manipulation of the argument mid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9792?
CVE-2025-9792 is classified as a high severity vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-9792?
To fix CVE-2025-9792, sanitize and validate all user inputs, particularly for the mid parameter in the /e_dashboard/e_all_info.php file.
Who is affected by CVE-2025-9792?
CVE-2025-9792 affects users of the itsourcecode Apartment Management System version 1.0.
Can CVE-2025-9792 be exploited remotely?
Yes, CVE-2025-9792 can be exploited remotely, allowing attackers to execute malicious SQL queries.
What component of the itsourcecode Apartment Management System is vulnerable in CVE-2025-9792?
The vulnerability in CVE-2025-9792 is found in the /e_dashboard/e_all_info.php file.