CVE-2025-4491: Campcodes Online Food Ordering System ticket-status.php sql injection
A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /routers/ticket-status.php. The manipulation of the argument ticketid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4491?
CVE-2025-4491 is classified as a critical vulnerability.
How do I fix CVE-2025-4491?
To fix CVE-2025-4491, sanitize user inputs to prevent SQL injection and update to the latest secure version of the Campcodes Online Food Ordering System.
What component is affected by CVE-2025-4491?
CVE-2025-4491 affects the file /routers/ticket-status.php in the Campcodes Online Food Ordering System.
What type of attack does CVE-2025-4491 facilitate?
CVE-2025-4491 facilitates remote SQL injection attacks through the manipulation of the argument ticket_id.
Who is affected by CVE-2025-4491?
Any user or organization using Campcodes Online Food Ordering System 1.0 is affected by CVE-2025-4491.