Description
A vulnerability was found in Campcodes Park Ticketing System 1.0. The impacted element is the function save_pricing of the file admin_class.php. The manipulation of the argument name/ride results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2025-12-28: | Advisory disclosed |
| 2025-12-28: | VulDB entry created |
| 2026-01-07: | VulDB entry last update |
Credits
doublekill182 (VulDB User)
References
vuldb.com/?id.338599 (VDB-338599 | Campcodes Park Ticketing System admin_class.php save_pricing cross site scripting)
vuldb.com/?ctiid.338599 (VDB-338599 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.725104 (Submit #725104 | Campcodes Park Ticketing System v1.0 XSS)
vuldb.com/?submit.728898 (Submit #728898 | campcodes Park Ticketing System V1.0 Cross Site Scripting (Duplicate))
github.com/dobkill/CVE/issues/2
www.campcodes.com/