CVE-2025-9008: itsourcecode Online Tour and Travel Management System sms_setting.php sql injection
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/smssetting.php. The manipulation of the argument uname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9008?
CVE-2025-9008 is classified as a high severity vulnerability due to its potential for SQL injection leading to unauthorized access and data manipulation.
How do I fix CVE-2025-9008?
To fix CVE-2025-9008, sanitize and validate user inputs in the /admin/sms_setting.php file to prevent SQL injection attacks.
What type of vulnerability is CVE-2025-9008?
CVE-2025-9008 is a SQL injection vulnerability that can be triggered by manipulating the 'uname' argument.
Can CVE-2025-9008 be exploited remotely?
Yes, CVE-2025-9008 can be exploited remotely, making it critical for affected users to apply security updates.
Which software is affected by CVE-2025-9008?
CVE-2025-9008 affects the itsourcecode Online Tour and Travel Management System version 1.0.