CVE-2025-9505: Campcodes Online Loan Management System ajax.php sql injection
A flaw has been found in Campcodes Online Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=saveloantype. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9505?
CVE-2025-9505 has a high severity due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-9505?
Fixing CVE-2025-9505 involves sanitizing user inputs to the /ajax.php?action=save_loan_type endpoint to prevent SQL injection.
What systems are affected by CVE-2025-9505?
CVE-2025-9505 affects Campcodes Online Loan Management System version 1.0.
Can CVE-2025-9505 be exploited remotely?
Yes, CVE-2025-9505 can be exploited remotely, allowing attackers to execute SQL queries.
What is the impact of not addressing CVE-2025-9505?
Failing to address CVE-2025-9505 can lead to unauthorized access to sensitive data through SQL injection.