CVE-2025-8967: itsourcecode Online Tour and Travel Management System packages.php sql injection
A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/packages.php. The manipulation of the argument pname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8967?
CVE-2025-8967 is classified as a high severity vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-8967?
To fix CVE-2025-8967, sanitize and validate user inputs in the `pname` parameter to prevent SQL injection.
What is affected by CVE-2025-8967?
CVE-2025-8967 affects the itsourcecode Online Tour and Travel Management System version 1.0.
Can CVE-2025-8967 be exploited remotely?
Yes, CVE-2025-8967 can be exploited remotely by an attacker through the vulnerable `packages.php` script.
What are the potential impacts of CVE-2025-8967?
The exploitation of CVE-2025-8967 can lead to unauthorized access to the database, data leakage, and possible complete takeover of the affected application.