PT-2025-34834 · Itsourcecode · Apartment Management System
Zzb1
·
Published
2025-08-27
·
Updated
2025-09-01
·
CVE-2025-9510
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
itsourcecode Apartment Management System version 1.0
Description:
A security issue has been identified in itsourcecode Apartment Management System version 1.0. The vulnerability is due to SQL injection in the
/branch/addbranch.php file. Manipulation of the ID parameter can lead to exploitation. The exploit has been publicly disclosed and may be used to initiate attacks remotely.Recommendations:
As a temporary workaround, consider restricting access to the
/branch/addbranch.php file until a fix is available.
Sanitize the ID parameter before using it in SQL queries.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apartment Management System