CVE-2025-8982: itsourcecode Online Tour and Travel Management System currency.php sql injection
A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/currency.php. The manipulation of the argument currcode leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8982?
CVE-2025-8982 has a high severity rating due to its potential for remote SQL injection.
How do I fix CVE-2025-8982?
To fix CVE-2025-8982, sanitize and validate the `curr_code` input in the `/admin/operations/currency.php` file to prevent SQL injection.
What components are affected by CVE-2025-8982?
CVE-2025-8982 affects the itsourcecode Online Tour and Travel Management System version 1.0.
Can CVE-2025-8982 be exploited remotely?
Yes, CVE-2025-8982 can be exploited remotely, making it a significant risk.
What types of attacks can be performed using CVE-2025-8982?
CVE-2025-8982 allows attackers to execute SQL injection attacks, which can compromise the database.