SQL Injection Vulnerability in Campcodes Supplier Management System
CVE-2025-13554
Key Information:
- Vendor
Campcodes
- Vendor
- CVE Published:
- 23 November 2025
Badges
What is CVE-2025-13554?
A security vulnerability has been identified in the Campcodes Supplier Management System (version 1.0). This flaw occurs within an unspecified function of the /index.php file related to the Login component. Attackers can exploit this vulnerability to manipulate the 'txtUsername' argument, which can lead to SQL injection attacks. The nature of this vulnerability allows for remote exploitation, posing a significant risk to systems utilizing this product. Public disclosure of the exploit has occurred, highlighting the necessity for immediate remediation to secure affected systems.
Affected Version(s)
Supplier Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
