CVE-2025-9529
BaseFortify
Publication date: 2025-08-27
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| campcodes | payroll_management_system | 1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-73 | The product allows user input to control or influence paths or file names that are used in filesystem operations. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a file inclusion weakness in the Campcodes Payroll Management System 1.0. It occurs in the include function of the /index.php file, where manipulation of the 'page' argument allows an attacker to include arbitrary files. This can be exploited remotely and the exploit is publicly available.
How can this vulnerability impact me? :
Exploitation of this vulnerability can allow an attacker to include and execute arbitrary files on the server, potentially leading to unauthorized access, data leakage, or system compromise. This can result in loss of confidentiality, integrity, and availability of the affected system.