Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rowantu

#25706of 53,622
9.8Total CVSS
Vulnerabilities · 1
PT-2025-41461
9.8
2025-10-09
Unknown · Campcodes Online Learning Management System · CVE-2025-11555
**Name of the Vulnerable Software and Affected Versions** Campcodes Online Learning Management System version 1.0 **Description** A SQL Injection issue exists in Campcodes Online Learning Management System version 1.0. The flaw is located within the `/admin/calendar of events.php` script, where the `date start` parameter can be manipulated to inject malicious SQL code. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the backend database, potentially leading to data leakage, data corruption, or unauthorized access. The exploit is publicly available. **Recommendations** Apply a fix for Campcodes Online Learning Management System version 1.0. As a temporary workaround, restrict access to the `/admin/calendar of events.php` script. Avoid using the `date start` parameter in the affected API endpoint until the issue is resolved.