Description
A vulnerability was found in Campcodes Park Ticketing System 1.0. The impacted element is the function save_pricing of the file admin_class.php. The manipulation of the argument name/ride results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.
References
https://github.com/dobkill/CVE/issues/2
ExploitIssue TrackingThird Party Advisory
https://vuldb.com/?ctiid.338599
Permissions RequiredVDB Entry
Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.725104
Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.728898
Third Party AdvisoryVDB Entry
Product
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
2.4 · Low
Information
Source identifier
Vulnerability status
Analyzed
Published
2025-12-30T02:16:16.593Z
2 weeks agoLast modified
2026-01-07T17:42:25.010Z
1 week ago