6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in Campcodes Online Flight Booking Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2025-8952
Source
VulDB
Published
Aug 14, 2025 at 08:32
Affected Product
Vendor
Campcodes
Product
Online Flight Booking Management System
Version
1.0
Affected Versions
Campcodes Online Flight Booking Management System 1.0