A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/operations/payment.php. The manipulation of the argument payment_type leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/operations/payment.php. The manipulation of the argument payment_type leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | itsourcecode Online Tour and Travel Management System payment.php sql injection | |
Weaknesses | CWE-74 CWE-89 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-14T20:02:06.015Z
Updated: 2025-08-14T20:11:40.969Z
Reserved: 2025-08-13T16:50:13.747Z
Link: CVE-2025-8981

No data.

Status : Awaiting Analysis
Published: 2025-08-14T20:15:38.603
Modified: 2025-08-15T13:12:51.217
Link: CVE-2025-8981

No data.