CVE-2025-9504 | Campcodes Online Loan Management System 1.0 ajax.php?action=save_plan ID sql injection
A vulnerability was found in Campcodes Online Loan Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_plan. The manipulation of the argument ID results in sql injection.
This vulnerability is identified as CVE-2025-9504. The attack can be executed remotely. Additionally, an exploit exists.