A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/packages.php. The manipulation of the argument pname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
History

Mon, 18 Aug 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mayurik
Mayurik online Tour \& Travel Management System
CPEs cpe:2.3:a:mayurik:online_tour_\&_travel_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Mayurik
Mayurik online Tour \& Travel Management System

Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode online Tour And Travel Management System
Vendors & Products Itsourcecode
Itsourcecode online Tour And Travel Management System

Thu, 14 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/packages.php. The manipulation of the argument pname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Title itsourcecode Online Tour and Travel Management System packages.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-08-14T16:02:06.735Z

Updated: 2025-08-14T18:24:53.166Z

Reserved: 2025-08-13T16:15:32.686Z

Link: CVE-2025-8967

cve-icon Vulnrichment

Updated: 2025-08-14T18:24:44.276Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-14T16:15:42.837

Modified: 2025-08-18T15:33:20.507

Link: CVE-2025-8967

cve-icon Redhat

No data.