CVE-2025-9009: itsourcecode Online Tour and Travel Management System email_setup.php sql injection
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/emailsetup.php. The manipulation of the argument Name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9009?
CVE-2025-9009 is considered a high-severity vulnerability due to its potential to allow remote SQL injection attacks.
How do I fix CVE-2025-9009?
To fix CVE-2025-9009, sanitize and validate the input in the /admin/email_setup.php file to prevent SQL injection.
What are the potential impacts of CVE-2025-9009?
CVE-2025-9009 could allow attackers to execute arbitrary SQL queries, leading to data leakage or manipulation.
Which versions of the Online Tour and Travel Management System are affected by CVE-2025-9009?
CVE-2025-9009 affects version 1.0 of the Online Tour and Travel Management System by itsourcecode.
Is CVE-2025-9009 easy to exploit?
Yes, CVE-2025-9009 is relatively easy to exploit due to its remote access capability and lack of input validation.