CVE-2025-13424: Campcodes Supplier Management System add_product.php sql injection
A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/addproduct.php. The manipulation of the argument txtProductName leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13424?
CVE-2025-13424 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
How can I fix CVE-2025-13424?
To fix CVE-2025-13424, apply input sanitization and parameterized queries to the function handling txtProductName in /admin/add_product.php.
What impacts does CVE-2025-13424 have on my system?
CVE-2025-13424 allows attackers to execute arbitrary SQL commands, potentially leading to unauthorized access or data manipulation.
Is CVE-2025-13424 easily exploitable?
Yes, CVE-2025-13424 can be easily exploited remotely without authentication, making it a significant security risk.
Which version of Campcodes Supplier Management System is affected by CVE-2025-13424?
CVE-2025-13424 affects Campcodes Supplier Management System version 1.0.