PT-2025-34713 · Itsourcecode · Apartment Management System
Zzb1
·
Published
2025-08-25
·
Updated
2025-08-26
·
CVE-2025-9420
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
itsourcecode Apartment Management System version 1.0
Description:
A flaw exists in itsourcecode Apartment Management System 1.0 that allows for SQL injection. The issue is located in the
/floor/addfloor.php file, where manipulation of the hdnid argument can trigger the injection. The attack can be launched remotely. The exploit has been published.Recommendations:
As a temporary workaround, consider restricting access to the
/floor/addfloor.php file until a fix is available.
Sanitize the hdnid argument to prevent SQL injection.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apartment Management System