CVE-2025-9529External Control of File Name or Path in Payroll Management System

Severity
6.9MEDIUMNVD
EPSS
0.1%
top 76.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27

Description

A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include of the file /index.php. This manipulation of the argument page causes file inclusion. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Campcodes Payroll Management System index.php include file inclusion2025-08-27
GHSA
GHSA-8j7v-6g8v-2256: A weakness has been identified in Campcodes Payroll Management System 12025-08-27
CVE-2025-9529 — External Control of File Name or Path | cvebase