CVE-2025-8983: itsourcecode Online Tour and Travel Management System expense.php sql injection
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/operations/expense.php. The manipulation of the argument expensefor leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8983?
CVE-2025-8983 is a critical vulnerability due to the potential for SQL injection, which can lead to unauthorized access to sensitive data.
How do I fix CVE-2025-8983?
To fix CVE-2025-8983, validate and sanitize user inputs especially in the expense_for parameter in the expense.php file.
What types of attacks can CVE-2025-8983 facilitate?
CVE-2025-8983 can facilitate SQL injection attacks, allowing attackers to manipulate database queries.
Which software is affected by CVE-2025-8983?
CVE-2025-8983 affects itsourcecode Online Tour and Travel Management System version 1.0.
Can CVE-2025-8983 be exploited remotely?
Yes, CVE-2025-8983 can be exploited remotely by an attacker targeting the affected application.