CVE-2025-6961: Campcodes Employee Management System mark.php sql injection
A vulnerability, which was classified as critical, has been found in Campcodes Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /mark.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6961?
CVE-2025-6961 is classified as a critical vulnerability in the Campcodes Employee Management System.
How do I fix CVE-2025-6961?
To remediate CVE-2025-6961, ensure that input sanitization and prepared statements are implemented in the application to protect against SQL injection.
What component is affected by CVE-2025-6961?
The vulnerability CVE-2025-6961 affects an unknown functionality in the file /mark.php of the Campcodes Employee Management System.
Can CVE-2025-6961 be exploited remotely?
Yes, CVE-2025-6961 can be exploited remotely, allowing attackers to manipulate the ID argument to perform SQL injection.
What kind of attack does CVE-2025-6961 allow?
CVE-2025-6961 allows SQL injection attacks due to improper handling of input in the affected file.