PT-2025-53801 · Campcodes · Campcodes Supplier Management System

Lige Zhan

·

Published

2025-12-29

·

Updated

2025-12-30

·

CVE-2025-15206

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Campcodes Supplier Management System version 1.0
Description A flaw exists in Campcodes Supplier Management System that allows for SQL injection. The issue is located in the file '/admin/add area.php' and involves manipulation of the txtAreaCode argument. This can be exploited remotely. The exploit has been published.
Recommendations Apply any available updates to address the vulnerability in the affected version. As a temporary workaround, restrict access to the file /admin/add area.php to minimize the risk of exploitation. Sanitize the txtAreaCode input to prevent SQL injection attacks.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-15206

Affected Products

Campcodes Supplier Management System