6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/packages.php. The manipulation of the argument pname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2025-8967
Source
VulDB
Published
Aug 14, 2025 at 16:02
Affected Product
Vendor
itsourcecode
Product
Online Tour and Travel Management System
Version
1.0
Affected Versions
itsourcecode Online Tour and Travel Management System 1.0