CVE-2025-9505 | Campcodes Online Loan Management System 1.0 ajax.php?action=save_loan_type ID sql injection
A vulnerability was found in Campcodes Online Loan Management System 1.0. It has been classified as critical. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_loan_type. This manipulation of the argument ID causes sql injection.
This vulnerability is tracked as CVE-2025-9505. The attack is possible to be carried out remotely. Moreover, an exploit is present.