CVE-2025-9010: itsourcecode Online Tour and Travel Management System booking_report.php sql injection
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/bookingreport.php. The manipulation of the argument fromdate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9010?
CVE-2025-9010 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2025-9010?
To fix CVE-2025-9010, sanitize and validate the input parameters used in the /admin/booking_report.php file.
What systems are affected by CVE-2025-9010?
CVE-2025-9010 affects itsourcecode Online Tour and Travel Management System version 1.0.
Can CVE-2025-9010 be exploited remotely?
Yes, CVE-2025-9010 can be exploited remotely through manipulated input parameters.
What type of attack can result from CVE-2025-9010?
CVE-2025-9010 can lead to SQL injection attacks that compromise database security.