CVE-2025-8993: itsourcecode Online Tour and Travel Management System expense_report.php sql injection
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/expensereport.php. The manipulation of the argument fromdate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8993?
CVE-2025-8993 is categorized as a high-severity vulnerability due to its potential for SQL injection and remote exploitation.
How do I fix CVE-2025-8993?
To fix CVE-2025-8993, sanitize and validate the 'from_date' input in the /admin/expense_report.php file to prevent SQL injection.
What impact does CVE-2025-8993 have on my application?
CVE-2025-8993 allows attackers to perform SQL injection, which can result in unauthorized data access and manipulation.
Is CVE-2025-8993 easy to exploit?
Yes, CVE-2025-8993 can be easily exploited remotely if the input validation is not properly handled.
What should I do if I am using an affected version of the Online Tour and Travel Management System?
If using the affected version of the Online Tour and Travel Management System, apply the recommended fix and consider upgrading to a secure version.