CNNVD-202512-5485 Information

CNNVD ID

CNNVD-202512-5485

CVE-2025-15214

  • CNNVD Published: 2025-12-30

Description (Chinese)

CampCodes Park Ticketing System是菲律宾CampCodes公司的一个公园售票系统。 CampCodes Park Ticketing System 1.0版本存在代码注入漏洞,该漏洞源于对文件admin_class.php中函数save_pricing的参数Name的错误操作,可能导致跨站脚本攻击。

Description (English)

CampCodes Park Ticking Systems is a park ticketing system for CampCodes in the Philippines. CampCodes Park Picking System Version 1.0 contains a code-in loophole that results from an error in the parameter of the function save pricing in file admin class.php, which may result in a cross-site script attack.

Hazard Level

Critical

Vulnerability Type

代码注入

Affected Vendor

CampCodes

Published

2025-12-30

Last Modified

2026-02-24

References

https://vuldb.com/?submit.728898 https://www.campcodes.com/ https://vuldb.com/?ctiid.338599 https://github.com/dobkill/CVE/issues/2 https://vuldb.com/?id.338599 https://vuldb.com/?submit.725104

Share on: