CVE-2025-5676: Campcodes Online Recruitment Management System ajax.php sql injection
A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5676?
CVE-2025-5676 has been declared as critical due to its potential for SQL injection.
How does CVE-2025-5676 impact the Campcodes Online Recruitment Management System?
CVE-2025-5676 affects the login functionality in the /admin/ajax.php file, allowing attackers to manipulate the Username argument.
How do I fix CVE-2025-5676?
To fix CVE-2025-5676, sanitize and validate user input in the login process to prevent SQL injection.
What type of injection is involved in CVE-2025-5676?
CVE-2025-5676 involves SQL injection, which allows attackers to execute arbitrary SQL code.
Who is affected by CVE-2025-5676?
Any user of the Campcodes Online Recruitment Management System version 1.0 may be affected by CVE-2025-5676.