SQL Injection Vulnerability in Campcodes Online Beauty Parlor Management System
CVE-2025-11664
Key Information:
- Vendor
Campcodes
- Vendor
- CVE Published:
- 13 October 2025
Badges
What is CVE-2025-11664?
A security vulnerability has been identified in Campcodes Online Beauty Parlor Management System version 1.0. This issue arises from an unprotected function located in the file /admin/search-appointment.php. By manipulating the 'searchdata' argument, an attacker can execute SQL injection attacks remotely. The vulnerability has already been made public, making it crucial for users of this system to take immediate action to secure their applications to prevent unauthorized database access.
Affected Version(s)
Online Beauty Parlor Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved