CVE-2025-9691: Campcodes Online Shopping System login.php sql injection
A vulnerability has been found in Campcodes Online Shopping System 1.0. This impacts an unknown function of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9691?
CVE-2025-9691 is classified as a high severity vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2025-9691?
To fix CVE-2025-9691, you should sanitize user inputs and validate the credentials in the /login.php file to prevent SQL injection.
What systems are affected by CVE-2025-9691?
CVE-2025-9691 affects Campcodes Online Shopping System version 1.0.
Can CVE-2025-9691 be exploited remotely?
Yes, CVE-2025-9691 can be exploited remotely by sending crafted requests to the vulnerable /login.php endpoint.
What type of attack does CVE-2025-9691 enable?
CVE-2025-9691 enables SQL injection attacks, allowing an attacker to manipulate the database.