PT-2025-26526 · Unknown · Campcodes Online Recruitment Management System

Sp1D3R

·

Published

2025-06-21

·

Updated

2025-06-22

·

CVE-2025-6422

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Campcodes Online Recruitment Management System version 1.0
Description: A critical issue was found in the system, affecting an unknown functionality of the file /admin/ajax.php?action=save settings, specifically the About Content Page component. The manipulation of the img argument leads to unrestricted upload. This issue can be exploited remotely.
Recommendations: For Campcodes Online Recruitment Management System version 1.0, as a temporary workaround, consider restricting access to the /admin/ajax.php?action=save settings endpoint to minimize the risk of exploitation. Avoid using the img argument in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-6422

Affected Products

Campcodes Online Recruitment Management System