Campcodes Online Beauty Parlor Management System SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Campcodes Online Beauty Parlor Management System version 1.0. The issue arises in the file '/admin/bwdates-reports-details.php', where the 'fromdate' and 'todate' parameters are manipulated, allowing for SQL injection attacks. This vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate database queries, potentially leading to unauthorized data access or modification.

Reproduction

To reproduce this vulnerability, log into the application and navigate to the admin reports section. Send a POST request to '/admin/bwdates-reports-details.php' with the 'fromdate' parameter set to a date value and the 'todate' parameter set to a later date. The SQL injection can be verified using the sqlmap tool, which will demonstrate the injection point and the ability to exploit the vulnerability by, for example, retrieving database information.

Added: Sep 22, 2025, 5:28 PM
Updated: Sep 23, 2025, 12:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.