CVE-2025-13554: Campcodes Supplier Management System Login index.php sql injection
A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. Such manipulation of the argument txtUsername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13554?
CVE-2025-13554 is a critical severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-13554?
Fix CVE-2025-13554 by sanitizing user inputs in the login functionality and using prepared statements to prevent SQL injection.
What component is affected by CVE-2025-13554?
CVE-2025-13554 affects the Login component of the Campcodes Supplier Management System 1.0.
Can CVE-2025-13554 be exploited remotely?
Yes, CVE-2025-13554 can be exploited remotely, making it a serious threat to users.
What can attackers do with CVE-2025-13554?
Attackers exploiting CVE-2025-13554 can manipulate database queries, potentially leading to unauthorized data access.