CVE-2025-9423: Campcodes Online Water Billing System editecex.php sql injection
Published Aug 25, 2025
·Updated
A vulnerability was determined in Campcodes Online Water Billing System 1.0. Affected is an unknown function of the file /editecex.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected Software
2 affected components
Campcodes Online Water Billing System
Campcodes Online Water Billing System=1.0
Event History
Aug 25, 2025
CVE Published
via MITRE·10:32 PM
Data Sourced
via MITRE·10:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 27, 57989
Event
via FIRST·11:12 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-9423?
CVE-2025-9423 has a high severity due to its potential for remote SQL injection exploitation.
2
How do I fix CVE-2025-9423?
To fix CVE-2025-9423, sanitize and validate all user inputs, particularly the ID parameter in the /editecex.php file.
3
Who is affected by CVE-2025-9423?
CVE-2025-9423 affects users of Campcodes Online Water Billing System version 1.0.
4
What type of vulnerability is CVE-2025-9423?
CVE-2025-9423 is classified as an SQL injection vulnerability.
5
Is CVE-2025-9423 remotely exploitable?
Yes, CVE-2025-9423 can be remotely exploited by an attacker.