File Inclusion Vulnerability in Campcodes Recruitment Management System
CVE-2025-9920
Key Information:
- Vendor
Campcodes
- Vendor
- CVE Published:
- 3 September 2025
Badges
What is CVE-2025-9920?
A security flaw has been identified in the Campcodes Recruitment Management System version 1.0, specifically affecting the inclusion functionality within the file located at /admin/index.php. This vulnerability arises from inadequate controls on the page argument, enabling an attacker to exploit the system via remote access. If exploited, this flaw could allow unauthorized file inclusion, potentially compromising the integrity and security of the application. It is essential for users of this system to apply necessary patches and implement security measures to safeguard against potential exploitation. For more details, visit Campcodes official website.
Affected Version(s)
Recruitment Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved