CVE-2025-9492: Campcodes Online Water Billing System addclient1.php sql injection
A vulnerability was determined in Campcodes Online Water Billing System 1.0. This affects an unknown function of the file /addclient1.php. Executing manipulation of the argument lname can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9492?
CVE-2025-9492 is considered a high severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-9492?
To fix CVE-2025-9492, sanitize and validate user inputs in the /addclient1.php file to prevent SQL injection.
Which software is affected by CVE-2025-9492?
CVE-2025-9492 affects Campcodes Online Water Billing System version 1.0.
Can CVE-2025-9492 be exploited remotely?
Yes, CVE-2025-9492 can be exploited remotely by manipulating the lname parameter.
What is the nature of the vulnerability in CVE-2025-9492?
The nature of the vulnerability in CVE-2025-9492 is an SQL injection vulnerability that allows attackers to manipulate database queries.