CVE-2025-6963: Campcodes Employee Management System myprofile.php sql injection
A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /myprofile.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6963?
CVE-2025-6963 is classified as a critical severity vulnerability.
What vulnerability affects the Campcodes Employee Management System?
CVE-2025-6963 affects the Campcodes Employee Management System due to a SQL injection vulnerability in the /myprofile.php file.
How does CVE-2025-6963 allow for exploitation?
CVE-2025-6963 can be exploited remotely through manipulation of the argument ID.
What type of vulnerability is CVE-2025-6963?
CVE-2025-6963 is a SQL injection vulnerability.
How can I mitigate the risks of CVE-2025-6963?
To mitigate CVE-2025-6963, it is recommended to sanitize user inputs and apply security patches provided by the vendor.