itsourcecode Online Tour and Travel Management是itsourcecode开源的一个在线旅游与旅行管理系统。 itsourcecode Online Tour and Travel Management 1.0版本存在注入漏洞,该漏洞源于对文件/admin/operations/payment.php中参数payment_type的错误操作导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| itsourcecode | Online Tour and Travel Management System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-8984 | 7.3 HIGH | itsourcecode Online Tour and Travel Management System expense_category.php sql injection |
| CVE-2025-8983 | 7.3 HIGH | itsourcecode Online Tour and Travel Management System expense.php sql injection |
| CVE-2025-8982 | 7.3 HIGH | itsourcecode Online Tour and Travel Management System currency.php sql injection |
| CVE-2025-8972 | 7.3 HIGH | itsourcecode Online Tour and Travel Management System page-login.php sql injection |
| CVE-2025-8971 | 7.3 HIGH | itsourcecode Online Tour and Travel Management System travellers.php sql injection |
| CVE-2025-8970 | 7.3 HIGH | itsourcecode Online Tour and Travel Management System booking.php sql injection |
| CVE-2025-8969 | 7.3 HIGH | itsourcecode Online Tour and Travel Management System approve_user.php sql injection |
| CVE-2025-8968 | 7.3 HIGH | itsourcecode Online Tour and Travel Management System disapprove_user.php sql injection |
| CVE-2025-8967 | 7.3 HIGH | itsourcecode Online Tour and Travel Management System packages.php sql injection |
| CVE-2025-8966 | 7.3 HIGH | itsourcecode Online Tour and Travel Management System tax.php sql injection |
No comments yet