PT-2024-29442 · Campcodes · Campcodes Supplier Management System

Chen Haokun

·

Published

2024-07-24

·

Updated

2024-08-01

·

CVE-2024-41550

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CampCodes Supplier Management System version 1.0
Description The issue concerns SQL injection. It can be exploited via the "Supply Management System/admin/view invoice items.php?id=" API endpoint, specifically through the id variable.
Recommendations For CampCodes Supplier Management System version 1.0, update the software to a version that fixes the SQL injection issue in the "Supply Management System/admin/view invoice items.php?id=" API endpoint. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-41550

Affected Products

Campcodes Supplier Management System