Itsourcecode · Itsourcecode Online Tour/Travel Management System · CVE-2025-9426
Name of the Vulnerable Software and Affected Versions:
itsourcecode Online Tour and Travel Management System version 1.0
Description:
A weakness exists in itsourcecode Online Tour and Travel Management System 1.0, affecting an unknown part of the file `/package.php`. Manipulation of the `subcatid` argument can lead to SQL injection. The attack can be performed remotely. The exploit has been made publicly available.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.