---
id: CVE-2025-9594
title: A vulnerability has been found in itsourcecode Apartment Management System 1.0
summary: >-
  A vulnerability has been found in itsourcecode Apartment Management System
  1.0. The affected element is an unknown function of the file
  /report/complain_info.php. The manipulation of the argument vid leads to sql
  injection. The attack is…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: admerc
product: apartment_management_system
affected:
  - apartment_management_system = 1.0
published: '2025-08-28'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9594'
references:
  - url: 'https://github.com/pjy2004/cve/issues/1'
    label: cna@vuldb.com
  - url: 'https://itsourcecode.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.321768'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.321768'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.636187'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00421
epssPercentile: 0.33764
ingestedAt: '2026-09-26T00:22:39.898Z'
---

## Overview

A vulnerability has been found in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /report/complain_info.php. The manipulation of the argument vid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

## Affected

- `apartment_management_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
