CVE-2025-7219: Campcodes Payroll Management System ajax.php sql injection
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /ajax.php?action=deleteallowances. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7219?
CVE-2025-7219 is classified as critical.
What vulnerability does CVE-2025-7219 expose?
CVE-2025-7219 exposes the system to SQL injection through the manipulation of the argument ID in the /ajax.php?action=delete_allowances function.
How can I check if my system is affected by CVE-2025-7219?
If you are using Campcodes Payroll Management System version 1.0, your system is potentially affected by CVE-2025-7219.
How do I fix CVE-2025-7219?
To fix CVE-2025-7219, you should apply an update or patch provided by Campcodes for the Payroll Management System software.
What are the implications of exploiting CVE-2025-7219?
Exploiting CVE-2025-7219 could allow attackers to execute arbitrary SQL commands, potentially compromising database integrity and confidentiality.