PT-2025-38687 · Unknown · Campcodes Online Learning Management System

Zzb2

·

Published

2025-09-22

·

Updated

2025-09-27

·

CVE-2025-10784

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Campcodes Online Learning Management System version 1.0
Description: A security issue exists in Campcodes Online Learning Management System. The manipulation of the subject code argument in the /admin/edit subject.php file leads to SQL injection. This issue is remotely exploitable. The exploit has been publicly disclosed.
Recommendations: As a temporary workaround, consider restricting access to the /admin/edit subject.php file to minimize the risk of exploitation. Sanitize the subject code argument to prevent SQL injection attacks.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10784

Affected Products

Campcodes Online Learning Management System