CVE-2025-11555: Campcodes Online Learning Management System calendar_of_events.php sql injection
A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/calendarofevents.php. The manipulation of the argument datestart results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11555?
CVE-2025-11555 has a high severity due to its potential for remote exploitation via SQL injection.
How do I fix CVE-2025-11555?
To fix CVE-2025-11555, sanitize and validate all user inputs in the affected /admin/calendar_of_events.php file.
What systems are affected by CVE-2025-11555?
CVE-2025-11555 affects Campcodes Online Learning Management System version 1.0.
Can CVE-2025-11555 be exploited remotely?
Yes, CVE-2025-11555 can be exploited remotely by manipulating the date_start parameter.
What are the potential impacts of CVE-2025-11555?
The potential impacts of CVE-2025-11555 include unauthorized database access, data leakage, and system compromise.