CVE-2025-11077

HIGH

Campcodes Online Learning Management System 1.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-11077. PoCs published by byteReaper77.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2025-11077, a blind SQL injection vulnerability in the Online Learning Management System. The exploit uses crafted POST requests to extract database information and includes time-based blind SQLi techniques.

Description

A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

Exploits (1)

nomisec WORKING POC 2 stars
by byteReaper77 · poc
https://github.com/byteReaper77/CVE-2025-11077

This repository contains a proof-of-concept exploit for CVE-2025-11077, a blind SQL injection vulnerability in the Online Learning Management System. The exploit uses crafted POST requests to extract database information and includes time-based blind SQLi techniques.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Online Learning Management System (version not specified)
No auth needed
Prerequisites: Access to the target system's add_content.php endpoint · Network connectivity to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.326117
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.326117
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.661155
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/AbcDzfq/testdeom/issues/1
Product product
https://www.campcodes.com/

Scores

CVSS v3 7.3
EPSS 0.0038
EPSS Percentile 29.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
campcodes/online_learning_management_system 1.0
Published Sep 27, 2025
Tracked Since Feb 18, 2026