CVE-2025-9155: itsourcecode Online Tour and Travel Management System forget_password.php sql injection
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown function of the file /user/forgetpassword.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9155?
CVE-2025-9155 has a high severity due to its potential for remote exploitation via SQL injection.
How do I fix CVE-2025-9155?
To fix CVE-2025-9155, implement input validation and use prepared statements to prevent SQL injection in the /user/forget_password.php file.
What systems are affected by CVE-2025-9155?
CVE-2025-9155 affects the itsourcecode Online Tour and Travel Management System version 1.0.
Can CVE-2025-9155 be exploited remotely?
Yes, CVE-2025-9155 can be exploited remotely by manipulating the email parameter in the vulnerable script.
What is the primary impact of CVE-2025-9155?
The primary impact of CVE-2025-9155 is unauthorized access to the database through SQL injection.