CVE-2025-11664: Campcodes Online Beauty Parlor Management System search-appointment.php sql injection
A security vulnerability has been detected in Campcodes Online Beauty Parlor Management System 1.0. The impacted element is an unknown function of the file /admin/search-appointment.php. Such manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11664?
CVE-2025-11664 is classified as a critical severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-11664?
To fix CVE-2025-11664, sanitize and parameterize the input used in the /admin/search-appointment.php file to prevent SQL injection.
Which software is affected by CVE-2025-11664?
CVE-2025-11664 affects Campcodes Online Beauty Parlor Management System version 1.0.
What type of vulnerability is CVE-2025-11664?
CVE-2025-11664 is an SQL injection vulnerability that can be exploited through the searchdata parameter.
Can CVE-2025-11664 lead to data breaches?
Yes, CVE-2025-11664 can lead to data breaches as an attacker could execute arbitrary SQL queries on the database.