Campcodes · Campcodes Complete Online Beauty Parlor Management System · CVE-2025-15188
**Name of the Vulnerable Software and Affected Versions**
Campcodes Complete Online Beauty Parlor Management System version 1.0
**Description**
A flaw exists in Campcodes Complete Online Beauty Parlor Management System 1.0 that could allow for cross site scripting. The issue is located in the `/admin/search-invoices.php` file, where manipulation of the `searchdata` argument can be exploited. The attack can be initiated remotely and the exploit has been publicly disclosed.
**Recommendations**
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the `/admin/search-invoices.php` file.