6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A flaw has been found in Campcodes Online Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_loan_type. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Basic Information
ID
CVE-2025-9505
Source
VulDB
Published
Aug 27, 2025 at 03:32
Affected Product
Vendor
Campcodes
Product
Online Loan Management System
Version
1.0
Affected Versions
Campcodes Online Loan Management System 1.0