CVE-2025-9922: Campcodes Sales and Inventory System index.php cross site scripting
A security vulnerability has been detected in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Such manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9922?
CVE-2025-9922 is classified as a medium severity vulnerability due to its potential for remote exploitation via cross site scripting.
How do I fix CVE-2025-9922?
To fix CVE-2025-9922, ensure that input validation is properly implemented in the /index.php file to prevent injection attacks.
What type of vulnerability is CVE-2025-9922?
CVE-2025-9922 is a cross site scripting (XSS) vulnerability that can be exploited through manipulated input.
Can CVE-2025-9922 be exploited remotely?
Yes, CVE-2025-9922 can be exploited remotely, allowing attackers to execute scripts in the context of the user's session.
Which software is affected by CVE-2025-9922?
CVE-2025-9922 affects Campcodes Sales and Inventory System version 1.0.