CVE-2025-8984: itsourcecode Online Tour and Travel Management System expense_category.php sql injection
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/expensecategory.php. The manipulation of the argument expensename leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8984?
CVE-2025-8984 is classified as a medium severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-8984?
To fix CVE-2025-8984, sanitize and validate input data for the 'expense_name' parameter in the expense_category.php file.
What type of vulnerability is CVE-2025-8984?
CVE-2025-8984 is a SQL injection vulnerability that exploits an insecure SQL query in the application.
Which system is affected by CVE-2025-8984?
CVE-2025-8984 affects the itsourcecode Online Tour and Travel Management System version 1.0.
What can attackers do with CVE-2025-8984?
Attackers can exploit CVE-2025-8984 to execute arbitrary SQL commands and potentially gain unauthorized access to the database.