A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/sms_setting.php. The manipulation of the argument uname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
History

Mon, 18 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mayurik
Mayurik online Tour \& Travel Management System
CPEs cpe:2.3:a:mayurik:online_tour_\&_travel_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Mayurik
Mayurik online Tour \& Travel Management System

Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode online Tour And Travel Management System
Vendors & Products Itsourcecode
Itsourcecode online Tour And Travel Management System

Fri, 15 Aug 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Aug 2025 04:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/sms_setting.php. The manipulation of the argument uname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Title itsourcecode Online Tour and Travel Management System sms_setting.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-08-15T04:02:06.016Z

Updated: 2025-08-15T16:17:13.774Z

Reserved: 2025-08-13T19:29:33.751Z

Link: CVE-2025-9008

cve-icon Vulnrichment

Updated: 2025-08-15T16:17:06.391Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-15T04:15:59.917

Modified: 2025-08-18T15:11:05.640

Link: CVE-2025-9008

cve-icon Redhat

No data.