CVE-2025-8968: itsourcecode Online Tour and Travel Management System disapprove_user.php sql injection
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/disapproveuser.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8968?
CVE-2025-8968 has been classified as a critical severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-8968?
To fix CVE-2025-8968, validate and sanitize all user input, particularly for the ID parameter in the /admin/disapprove_user.php file.
What systems are affected by CVE-2025-8968?
CVE-2025-8968 affects version 1.0 of the itsourcecode Online Tour and Travel Management System.
What type of attack can be executed using CVE-2025-8968?
An attacker can execute a remote SQL injection attack by manipulating the ID parameter in the vulnerable script.
Are there any known exploits for CVE-2025-8968?
Yes, there are known exploits available that leverage the SQL injection vulnerability in CVE-2025-8968.