6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A security vulnerability has been detected in Campcodes Online Loan Management System 1.0. Affected is an unknown function of the file /ajax.php?action=save_borrower. The manipulation of the argument lastname leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Basic Information
ID
CVE-2025-9503
Source
VulDB
Published
Aug 27, 2025 at 03:02
Affected Product
Vendor
Campcodes
Product
Online Loan Management System
Version
1.0
Affected Versions
Campcodes Online Loan Management System 1.0