PT-2026-30431 · Campcodes · Complete Pos Management/Inventory System

Chenkh

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5561

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability was determined in Campcodes Complete POS Management and Inventory System up to 4.0.6. This affects an unknown function of the file app/Http/Controllers/SettingsController.php of the component Environment Variable Handler. Executing a manipulation can lead to injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

Exploit

Fix

Improper Neutralization

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5561

Affected Products

Complete Pos Management/Inventory System