CVE-2025-8966: itsourcecode Online Tour and Travel Management System tax.php sql injection
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/operations/tax.php. The manipulation of the argument tname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8966?
CVE-2025-8966 has a high severity due to its potential to allow SQL injection attacks.
How do I fix CVE-2025-8966?
To fix CVE-2025-8966, sanitize input parameters and use prepared statements to mitigate SQL injection vulnerabilities.
What software is affected by CVE-2025-8966?
CVE-2025-8966 affects the itsourcecode Online Tour and Travel Management System version 1.0.
Can CVE-2025-8966 be exploited remotely?
Yes, CVE-2025-8966 can be exploited remotely, allowing attackers to manipulate the SQL queries.
What is the primary impact of CVE-2025-8966?
The primary impact of CVE-2025-8966 is unauthorized access to the database through SQL injection.