Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25870 | A vulnerability was detected in Campcodes Online Loan Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_plan. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. |
Tue, 02 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:campcodes:online_loan_management_system:1.0:*:*:*:*:*:*:* |
Wed, 27 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 Aug 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Campcodes
Campcodes online Loan Management System |
|
| Vendors & Products |
Campcodes
Campcodes online Loan Management System |
Wed, 27 Aug 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Campcodes Online Loan Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_plan. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Title | Campcodes Online Loan Management System ajax.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-27T16:09:11.967Z
Reserved: 2025-08-26T20:11:11.648Z
Link: CVE-2025-9504
Updated: 2025-08-27T16:09:07.895Z
Status : Analyzed
Published: 2025-08-27T04:16:03.283
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-9504
No data.
OpenCVE Enrichment
Updated: 2025-08-27T11:21:26Z
EUVD