CVE-2025-9154: itsourcecode Online Tour and Travel Management System page-login.php sql injection
A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /user/page-login.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9154?
CVE-2025-9154 is considered a critical vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-9154?
To fix CVE-2025-9154, it is recommended to sanitize user inputs and use prepared statements in the /user/page-login.php file.
What software is affected by CVE-2025-9154?
CVE-2025-9154 affects the itsourcecode Online Tour and Travel Management System version 1.0.
Can CVE-2025-9154 be exploited remotely?
Yes, the exploit for CVE-2025-9154 can be initiated remotely, making it a significant security risk.
What kind of attack can CVE-2025-9154 lead to?
CVE-2025-9154 can lead to SQL injection attacks, potentially compromising sensitive database information.