CVE-2025-9793: itsourcecode Apartment Management System Setting admin.php sql injection
A vulnerability was detected in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /setting/admin.php of the component Setting Handler. Performing manipulation of the argument ddlBranch results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9793?
CVE-2025-9793 is classified as a medium severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-9793?
To fix CVE-2025-9793, sanitize and validate user inputs in the ddlBranch argument to prevent SQL injection.
What components of the Apartment Management System are affected by CVE-2025-9793?
CVE-2025-9793 affects the Setting Handler component, particularly the file /setting/admin.php.
Can CVE-2025-9793 lead to unauthorized access?
Yes, CVE-2025-9793 can allow attackers to manipulate the database, potentially leading to unauthorized access.
Is CVE-2025-9793 exploitable remotely?
Yes, CVE-2025-9793 can be exploited remotely if an attacker can send crafted requests to the affected system.