CVE-2025-9750: SQL Injection in Campcodes Online Learning Management System
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument Username results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
AI Analysis
Technical Summary
CVE-2025-9750 is a SQL Injection vulnerability identified in version 1.0 of the Campcodes Online Learning Management System (LMS). The flaw exists in the /admin/login.php file, specifically in the handling of the 'Username' parameter. An attacker can manipulate this parameter to inject malicious SQL code, which the backend database executes. This vulnerability is remotely exploitable without requiring authentication or user interaction, making it particularly dangerous. The CVSS 4.0 base score is 6.9 (medium severity), reflecting the ease of exploitation (network vector, no privileges required) and the potential impact on confidentiality, integrity, and availability, albeit with limited scope and impact. The vulnerability allows attackers to potentially bypass authentication, extract sensitive data, modify or delete data, or disrupt service availability. Although no public exploit is confirmed to be in widespread use, a proof-of-concept exploit has been released publicly, increasing the risk of exploitation. The lack of a patch or mitigation guidance from the vendor at this time further elevates the risk for organizations using this LMS version. Given the LMS context, educational institutions and organizations relying on Campcodes LMS are at risk of data breaches, unauthorized access, and operational disruption.
Potential Impact
For European organizations, especially educational institutions, training providers, and corporate learning departments using Campcodes LMS 1.0, this vulnerability poses significant risks. Exploitation could lead to unauthorized access to administrative functions, exposing sensitive user data such as personal information, academic records, and credentials. Data integrity could be compromised, affecting the reliability of educational records and assessments. Availability impacts could disrupt learning activities and administrative operations, causing reputational damage and compliance issues under GDPR due to potential data breaches. The remote, unauthenticated nature of the exploit increases the attack surface, making it easier for threat actors to target European entities without needing insider access. The public availability of exploit code further elevates the threat level, potentially leading to automated attacks or widespread exploitation campaigns targeting vulnerable LMS installations across Europe.
Mitigation Recommendations
European organizations should immediately audit their LMS deployments to identify any instances of Campcodes Online Learning Management System version 1.0. Given the absence of an official patch, organizations should implement compensating controls such as deploying Web Application Firewalls (WAFs) with specific rules to detect and block SQL injection attempts targeting the /admin/login.php endpoint and the 'Username' parameter. Input validation and parameterized queries should be enforced if organizations have the capability to modify the LMS codebase. Restricting network access to the LMS admin interface to trusted IP ranges or VPNs can reduce exposure. Continuous monitoring of logs for suspicious login attempts or SQL errors indicative of injection attempts is critical. Organizations should also prepare incident response plans for potential data breaches and consider isolating the LMS environment until a vendor patch is available. Engaging with the vendor for updates and applying patches promptly upon release is essential.
Affected Countries
Germany, France, United Kingdom, Italy, Spain, Netherlands, Sweden, Poland
CVE-2025-9750: SQL Injection in Campcodes Online Learning Management System
Description
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument Username results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
AI-Powered Analysis
Technical Analysis
CVE-2025-9750 is a SQL Injection vulnerability identified in version 1.0 of the Campcodes Online Learning Management System (LMS). The flaw exists in the /admin/login.php file, specifically in the handling of the 'Username' parameter. An attacker can manipulate this parameter to inject malicious SQL code, which the backend database executes. This vulnerability is remotely exploitable without requiring authentication or user interaction, making it particularly dangerous. The CVSS 4.0 base score is 6.9 (medium severity), reflecting the ease of exploitation (network vector, no privileges required) and the potential impact on confidentiality, integrity, and availability, albeit with limited scope and impact. The vulnerability allows attackers to potentially bypass authentication, extract sensitive data, modify or delete data, or disrupt service availability. Although no public exploit is confirmed to be in widespread use, a proof-of-concept exploit has been released publicly, increasing the risk of exploitation. The lack of a patch or mitigation guidance from the vendor at this time further elevates the risk for organizations using this LMS version. Given the LMS context, educational institutions and organizations relying on Campcodes LMS are at risk of data breaches, unauthorized access, and operational disruption.
Potential Impact
For European organizations, especially educational institutions, training providers, and corporate learning departments using Campcodes LMS 1.0, this vulnerability poses significant risks. Exploitation could lead to unauthorized access to administrative functions, exposing sensitive user data such as personal information, academic records, and credentials. Data integrity could be compromised, affecting the reliability of educational records and assessments. Availability impacts could disrupt learning activities and administrative operations, causing reputational damage and compliance issues under GDPR due to potential data breaches. The remote, unauthenticated nature of the exploit increases the attack surface, making it easier for threat actors to target European entities without needing insider access. The public availability of exploit code further elevates the threat level, potentially leading to automated attacks or widespread exploitation campaigns targeting vulnerable LMS installations across Europe.
Mitigation Recommendations
European organizations should immediately audit their LMS deployments to identify any instances of Campcodes Online Learning Management System version 1.0. Given the absence of an official patch, organizations should implement compensating controls such as deploying Web Application Firewalls (WAFs) with specific rules to detect and block SQL injection attempts targeting the /admin/login.php endpoint and the 'Username' parameter. Input validation and parameterized queries should be enforced if organizations have the capability to modify the LMS codebase. Restricting network access to the LMS admin interface to trusted IP ranges or VPNs can reduce exposure. Continuous monitoring of logs for suspicious login attempts or SQL errors indicative of injection attempts is critical. Organizations should also prepare incident response plans for potential data breaches and consider isolating the LMS environment until a vendor patch is available. Engaging with the vendor for updates and applying patches promptly upon release is essential.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-08-31T08:16:36.362Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68b4d814ad5a09ad00c3cecf
Added to database: 8/31/2025, 11:17:40 PM
Last enriched: 9/8/2025, 12:41:07 AM
Last updated: 10/17/2025, 12:31:25 AM
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
CVE-2025-23073: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Wikimedia Foundation Mediawiki - GlobalBlocking Extension
LowCVE-2025-62504: CWE-416: Use After Free in envoyproxy envoy
MediumCVE-2025-11864: Server-Side Request Forgery in NucleoidAI Nucleoid
MediumCVE-2024-42192: CWE-522 Insufficiently Protected Credentials in HCL Software Traveler for Microsoft Outlook
MediumCVE-2025-60358: n/a
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.