CVE-2025-7129: Campcodes Payroll Management System ajax.php sql injection
A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=deleteemployeeattendancesingle. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7129?
CVE-2025-7129 is classified as a critical vulnerability.
What type of vulnerability is CVE-2025-7129?
CVE-2025-7129 is a SQL injection vulnerability affecting the Campcodes Payroll Management System.
How does CVE-2025-7129 affect the Campcodes Payroll Management System?
CVE-2025-7129 allows attackers to manipulate the ID argument in the /ajax.php?action=delete_employee_attendance_single file, leading to unauthorized database access.
How can I mitigate the risks associated with CVE-2025-7129?
To mitigate CVE-2025-7129, validate and sanitize all user inputs, especially for the ID parameter.
Is there a patch available for CVE-2025-7129?
As of now, check with Campcodes for any available patches or updates that address CVE-2025-7129.