Description


A vulnerability was found in Campcodes Park Ticketing System 1.0. The impacted element is the function save_pricing of the file admin_class.php. The manipulation of the argument name/ride results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.

Related CPE's


References


https://github.com/dobkill/CVE/issues/2

ExploitIssue TrackingThird Party Advisory

https://vuldb.com/?ctiid.338599

Permissions RequiredVDB Entry

https://vuldb.com/?id.338599

Third Party AdvisoryVDB Entry

https://vuldb.com/?submit.725104

Third Party AdvisoryVDB Entry

https://vuldb.com/?submit.728898

Third Party AdvisoryVDB Entry

Weaknesses



CWE-79CWE-94

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

2.4 · Low

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2025-12-30T02:16:16.593Z

2 weeks ago

Last modified

2026-01-07T17:42:25.010Z

1 week ago