PT-2025-47108 · Campcodes · Campcodes Supplier Management System

0X0A1Lphj

·

Published

2025-11-17

·

Updated

2025-11-17

·

CVE-2025-13260

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Campcodes Supplier Management System version 1.0
Description A flaw exists in Campcodes Supplier Management System version 1.0 that allows for SQL injection. This issue affects an unknown function within the
/manufacturer/edit product.php
file. Manipulation of the
cmbProductUnit
argument can lead to a successful attack, which can be launched remotely. The exploit for this issue has been publicly disclosed.
Recommendations Campcodes Supplier Management System version 1.0: As a temporary workaround, consider restricting access to the
/manufacturer/edit product.php
file to minimize the risk of exploitation. Avoid using the
cmbProductUnit
parameter in the affected file until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-13260

Affected Products

Campcodes Supplier Management System