CVE-2025-8967
itsourcecode Online Tour and Travel Management System packages.php sql injection
A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/packages.php. The manipulation of the argument pname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
itsourcecode · Online Tour and Travel Management System¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →