PT-2025-35166 · Itsourcecode · Apartment Management System

Zzb2

·

Published

2025-08-29

·

Updated

2025-09-03

·

CVE-2025-9601

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions itsourcecode Apartment Management System version 1.0
Description A SQL injection issue exists in the /setting/employee salary setup.php file. The ddlEmpName argument is susceptible to manipulation, potentially allowing for remote exploitation. The exploit is publicly available.
Recommendations Sanitize or validate the ddlEmpName argument to prevent SQL injection. Restrict access to the /setting/employee salary setup.php file.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-9601

Affected Products

Apartment Management System