SQL Injection Vulnerability in Campcodes Employee Management System
CVE-2025-6963
What is CVE-2025-6963?
A vulnerability has been identified in Campcodes Employee Management System version 1.0, which involves the manipulation of an argument in the /myprofile.php file. This flaw allows an attacker to execute unauthorized SQL commands by exploiting the input parameter ID, leading to the potential exposure of sensitive data and system integrity compromise. The vulnerability can be exploited remotely, and public disclosure of the exploit means that systems running the affected version are particularly at risk. It is crucial for users of this software to review their security measures and apply necessary patches to mitigate this threat.
Affected Version(s)
Employee Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved