CVE-2025-9471
🔴 HIGHA vulnerability has been found in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /maintenance/add_maintenance_cost.php. The manipulation of the argum...
Expert Analysis 1 reviews
Expert Consensus
CEO VMR LLC
Over a dozen years of experience leading VM at some of the largest enterprises on earth
Web Security • Penetration Testing • Cloud Security
SQL Injection in Apartment Management System Maintenance Module
This vulnerability represents a severe security flaw in the itsourcecode Apartment Management System v1.0. The SQL injection in /maintenance/add_maintenance_cost.php poses risk to organizations using this software. The vulnerable endpoint fails to sanitize the id parameter before SQL queries, allowing arbitrary SQL command injection. Impact includes complete database access, tenant data exposure, financial record manipulation, and potential system takeover. Exploitation is trivial with public exploits available. CVSS 7.3 reflects high severity, but contextual risk pushes this to critical priority.
💡 Mitigation Advice
Immediate: Restrict /maintenance/ directory access via .htaccess. Deploy WAF rules blocking SQL patterns. Short-term: Apply vendor patches, implement parameterized queries, validate all inputs. Long-term: Complete security audit, secure coding training, consider alternative solutions. Monitor for UNION SELECT patterns in logs.
Community Discussion
No comments yet. Be the first to share your thoughts!
Full Description
A vulnerability has been found in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /maintenance/add_maintenance_cost.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
CVSS Scores
References
Additional Information
- Source
- cna@vuldb.com
- State
- Undergoing analysis
Related CVEs
CVE-2026-3380
HIGHA vulnerability was found in Tenda F453 1.0.0.3. This issue affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argumen...
CVE-2026-3379
HIGHA vulnerability has been found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipul...
CVE-2026-3378
HIGHA flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the...
CVE-2026-3377
HIGHA vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Perfor...
CVE-2026-3376
HIGHA security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromSafeMacFilter of the file /goform...
CVE-2026-28562
HIGHwpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql(...
Share CVE-2025-9471
Share on Social Media
Copy Link
Embed Code
Request Expert Analysis
Request a professional security analysis for CVE-2025-9471 from our verified experts.
Credits System
Use your credits to get expert analysis from verified security professionals. Purchase more credits anytime!