CVE-2025-9506: Campcodes Online Loan Management System ajax.php sql injection
A vulnerability has been found in Campcodes Online Loan Management System 1.0. This affects an unknown part of the file /ajax.php?action=deleteplan. Such manipulation of the argument ID leads to sql injection. The attack may be performed from a remote location. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9506?
CVE-2025-9506 is classified as a high-severity SQL injection vulnerability that can be exploited remotely.
How do I fix CVE-2025-9506?
To fix CVE-2025-9506, sanitize and validate all user inputs in the /ajax.php?action=delete_plan file to prevent SQL injection attacks.
What are the potential impacts of CVE-2025-9506?
Exploitation of CVE-2025-9506 could allow unauthorized access to the database and the extraction of sensitive information.
Which systems are affected by CVE-2025-9506?
CVE-2025-9506 affects Campcodes Online Loan Management System version 1.0.
Can CVE-2025-9506 be exploited from a remote location?
Yes, CVE-2025-9506 can be exploited from a remote location, allowing attackers to manipulate the ID argument.