CVE-2025-8952: Campcodes Online Flight Booking Management System Login ajax.php sql injection
A vulnerability was found in Campcodes Online Flight Booking Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8952?
CVE-2025-8952 has a critical severity level due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2025-8952?
To fix CVE-2025-8952, sanitize and validate the 'Username' input to prevent SQL injection.
What systems are affected by CVE-2025-8952?
CVE-2025-8952 affects Campcodes Online Flight Booking Management System version 1.0.
Can CVE-2025-8952 lead to unauthorized access?
Yes, exploitation of CVE-2025-8952 can lead to unauthorized access to the database.
What are the potential impacts of CVE-2025-8952?
The potential impacts of CVE-2025-8952 include data leakage, data alteration, and full system compromise.