Vulnerability Description
A weakness has been identified in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /employee/addemployee.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Admerc | Apartment Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/zzb1388/cve/issues/41ExploitIssue TrackingThird Party Advisory
- https://itsourcecode.com/Product
- https://vuldb.com/?ctiid.321260Permissions RequiredVDB Entry
- https://vuldb.com/?id.321260Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.634073Third Party AdvisoryVDB Entry
FAQ
What is CVE-2025-9417?
CVE-2025-9417 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A weakness has been identified in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /employee/addemployee.php. This manipulation of the argument ID c...
How severe is CVE-2025-9417?
CVE-2025-9417 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-9417?
Check the references section above for vendor advisories and patch information. Affected products include: Admerc Apartment Management System.