PT-2025-35157 · Itsourcecode · Apartment Management System
Zzb2
·
Published
2025-08-29
·
Updated
2025-09-03
·
CVE-2025-9598
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
itsourcecode Apartment Management System version 1.0
Description
A security flaw exists in itsourcecode Apartment Management System 1.0. The issue involves SQL injection in the
/setting/year setup.php file through manipulation of the txtXYear argument. This can be initiated remotely. The exploit has been released publicly.Recommendations
As a temporary workaround, consider restricting access to the
/setting/year setup.php file to minimize the risk of exploitation.
Avoid using the txtXYear argument in the affected file until the issue is resolved.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apartment Management System