PT-2025-29318 · Campcodes · Campcodes Sales/Inventory System

·

CVE-2025-7470

·

Published

2025-07-12

·

Updated

2025-07-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Campcodes Sales and Inventory System version 1.0
Description: A critical issue exists in Campcodes Sales and Inventory System 1.0, allowing for unrestricted file upload. The vulnerability is located in an unknown function within the /pages/product add.php file. Exploitation occurs through manipulation of the image argument, enabling remote attacks. The exploit details have been publicly disclosed.
Recommendations: Apply any available updates to address the unrestricted upload issue in the /pages/product add.php file. As a temporary workaround, restrict or disable file upload functionality to mitigate the risk of exploitation.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7470

Affected Products

Campcodes Sales/Inventory System