CVE-2025-9506
27.08.2025, 04:16
A vulnerability has been found in Campcodes Online Loan Management System 1.0. This affects an unknown part of the file /ajax.php?action=delete_plan. Such manipulation of the argument ID leads to sql injection. The attack may be performed from a remote location. The exploit has been disclosed to the public and may be used.
Vendor | Product | Version |
---|---|---|
campcodes | online_loan_management_system | 1.0 |
𝑥
= Vulnerable software versions