CVE-2025-9923: Campcodes Sales and Inventory System index.php cross site scripting
A flaw has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /index.php. Executing manipulation of the argument page can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9923?
CVE-2025-9923 is classified as a medium to high severity vulnerability due to its potential for remote exploitation via cross-site scripting.
How do I fix CVE-2025-9923?
To fix CVE-2025-9923, you should sanitize and validate the input for the argument page in the /index.php file to prevent cross-site scripting.
Who is affected by CVE-2025-9923?
CVE-2025-9923 affects users of Campcodes Sales and Inventory System version 1.0.
Can CVE-2025-9923 be exploited remotely?
Yes, CVE-2025-9923 can be exploited remotely, allowing attackers to execute cross-site scripting attacks.
What part of the software does CVE-2025-9923 impact?
CVE-2025-9923 impacts the /index.php file within the Campcodes Sales and Inventory System.