CVE-2025-9503: Campcodes Online Loan Management System ajax.php sql injection
A security vulnerability has been detected in Campcodes Online Loan Management System 1.0. Affected is an unknown function of the file /ajax.php?action=saveborrower. The manipulation of the argument lastname leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9503?
CVE-2025-9503 is identified as a high-severity SQL injection vulnerability.
How do I fix CVE-2025-9503?
To fix CVE-2025-9503, sanitize and validate the 'lastname' parameter in the /ajax.php?action=save_borrower function to prevent SQL injection.
What is the potential impact of CVE-2025-9503?
The potential impact of CVE-2025-9503 includes unauthorized access to the database and manipulation of sensitive data.
Who is affected by CVE-2025-9503?
CVE-2025-9503 affects users of Campcodes Online Loan Management System version 1.0.
Is remote exploitation possible with CVE-2025-9503?
Yes, remote exploitation of CVE-2025-9503 is possible due to the nature of the SQL injection vulnerability.