CVE-2025-7220: Campcodes Payroll Management System ajax.php sql injection
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=savedeductions. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7220?
CVE-2025-7220 has been declared as critical.
How do I fix CVE-2025-7220?
To mitigate CVE-2025-7220, ensure that all user inputs are properly sanitized to prevent SQL injection.
Which system is affected by CVE-2025-7220?
CVE-2025-7220 affects Campcodes Payroll Management System version 1.0.
What type of vulnerability is CVE-2025-7220?
CVE-2025-7220 is a SQL injection vulnerability that occurs through the argument ID in the /ajax.php?action=save_deductions functionality.
Can CVE-2025-7220 lead to unauthorized access?
Yes, CVE-2025-7220 can potentially allow attackers to manipulate the database and gain unauthorized access to sensitive data.