PT-2025-29318 · Campcodes · Campcodes Sales/Inventory System
Angel9
·
Published
2025-07-12
·
Updated
2025-07-17
·
CVE-2025-7470
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Campcodes Sales and Inventory System version 1.0
Description:
A critical issue exists in Campcodes Sales and Inventory System 1.0, allowing for unrestricted file upload. The vulnerability is located in an unknown function within the
/pages/product add.php file. Exploitation occurs through manipulation of the image argument, enabling remote attacks. The exploit details have been publicly disclosed.Recommendations:
Apply any available updates to address the unrestricted upload issue in the
/pages/product add.php file.
As a temporary workaround, restrict or disable file upload functionality to mitigate the risk of exploitation.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Campcodes Sales/Inventory System