CVE-2025-9471

🔴 HIGH

A vulnerability has been found in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /maintenance/add_maintenance_cost.php. The manipulation of the argum...

Published
Aug 26, 2025
Last Modified
Aug 26, 2025
Views
51
Bookmarks
0

Expert Analysis 1 reviews

Expert Consensus

7.8/10
Average Score
⚡ Patch Immediately
Albert Ross
Albert Ross ✅ Verified

CEO VMR LLC

Over a dozen years of experience leading VM at some of the largest enterprises on earth

Web Security • Penetration Testing • Cloud Security

7.8/10
Patch Immediately
SQL Injection in Apartment Management System Maintenance Module

This vulnerability represents a severe security flaw in the itsourcecode Apartment Management System v1.0. The SQL injection in /maintenance/add_maintenance_cost.php poses risk to organizations using this software. The vulnerable endpoint fails to sanitize the id parameter before SQL queries, allowing arbitrary SQL command injection. Impact includes complete database access, tenant data exposure, financial record manipulation, and potential system takeover. Exploitation is trivial with public exploits available. CVSS 7.3 reflects high severity, but contextual risk pushes this to critical priority.

💡 Mitigation Advice

Immediate: Restrict /maintenance/ directory access via .htaccess. Deploy WAF rules blocking SQL patterns. Short-term: Apply vendor patches, implement parameterized queries, validate all inputs. Long-term: Complete security audit, secure coding training, consider alternative solutions. Monitor for UNION SELECT patterns in logs.

2 months ago
0% helpful 0 votes

Community Discussion

No comments yet. Be the first to share your thoughts!

Full Description

A vulnerability has been found in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /maintenance/add_maintenance_cost.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

CVSS Scores

CVSS 3.1 7.3
7.3
HIGH
CVSS 2.0 7.3

Additional Information

Source
cna@vuldb.com
State
Undergoing analysis

Share CVE-2025-9471

Share on Social Media

Copy Link

Embed Code

Request Expert Analysis

Request a professional security analysis for CVE-2025-9471 from our verified experts.

Credits System

Use your credits to get expert analysis from verified security professionals. Purchase more credits anytime!

Add 3 credits for accelerated delivery

Base Cost: 8 credits
Priority Upgrade: + credits
SLA Acceleration: +3 credits
Total Cost:
Your Balance:

Insufficient Credits

You need more credits to submit this request.

Buy Credits

Report Analysis