CVE-2025-9744: Campcodes Online Loan Management System ajax.php sql injection
A weakness has been identified in Campcodes Online Loan Management System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Executing manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9744?
CVE-2025-9744 is classified with a high severity due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-9744?
To fix CVE-2025-9744, ensure proper input validation and use prepared statements to prevent SQL injection in the login function.
Can CVE-2025-9744 be exploited remotely?
Yes, CVE-2025-9744 can be exploited remotely by an attacker manipulating the Username parameter.
What version of Campcodes Online Loan Management System is affected by CVE-2025-9744?
CVE-2025-9744 affects the Campcodes Online Loan Management System version 1.0.
What kind of vulnerability is CVE-2025-9744?
CVE-2025-9744 is an SQL injection vulnerability that can compromise the security of the application.