CVE-2025-7135: Campcodes Online Recruitment Management System ajax.php sql injection
A vulnerability, which was classified as critical, has been found in Campcodes Online Recruitment Management System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=savevacancy. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7135?
CVE-2025-7135 is classified as a critical vulnerability.
How do I fix CVE-2025-7135?
To fix CVE-2025-7135, it is recommended to sanitize user inputs and implement prepared statements in the SQL queries for the affected script.
What type of vulnerability is CVE-2025-7135?
CVE-2025-7135 is an SQL injection vulnerability affecting the Campcodes Online Recruitment Management System.
Which component is affected by CVE-2025-7135?
CVE-2025-7135 affects the /admin/ajax.php?action=save_vacancy file in the Campcodes Online Recruitment Management System.
Can CVE-2025-7135 lead to data breaches?
Yes, exploitation of CVE-2025-7135 can allow attackers to execute arbitrary SQL commands, potentially leading to data breaches.