PT-2025-41461 · Unknown · Campcodes Online Learning Management System

Rowan

+1

·

Published

2025-10-09

·

Updated

2025-10-20

·

CVE-2025-11555

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Campcodes Online Learning Management System version 1.0
Description A SQL Injection issue exists in Campcodes Online Learning Management System version 1.0. The flaw is located within the /admin/calendar of events.php script, where the date start parameter can be manipulated to inject malicious SQL code. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the backend database, potentially leading to data leakage, data corruption, or unauthorized access. The exploit is publicly available.
Recommendations Apply a fix for Campcodes Online Learning Management System version 1.0. As a temporary workaround, restrict access to the /admin/calendar of events.php script. Avoid using the date start parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-11555

Affected Products

Campcodes Online Learning Management System