CVE-2025-9529: Campcodes Payroll Management System index.php include file inclusion
A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include of the file /index.php. This manipulation of the argument page causes file inclusion. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9529?
CVE-2025-9529 is considered a high-severity vulnerability due to its potential for remote exploitation through file inclusion.
How do I fix CVE-2025-9529?
To fix CVE-2025-9529, ensure that the input for the 'page' parameter is properly validated and sanitized to prevent unauthorized file inclusion.
What are the potential impacts of CVE-2025-9529?
The potential impacts of CVE-2025-9529 include unauthorized access to sensitive files and possible complete compromise of the affected system.
Who is affected by CVE-2025-9529?
CVE-2025-9529 affects users of Campcodes Payroll Management System 1.0 that utilize the vulnerable '/index.php' function.
Can CVE-2025-9529 be exploited remotely?
Yes, CVE-2025-9529 can be exploited remotely, allowing attackers to manipulate the input for file inclusion without local access.