CVE-2025-14664: Campcodes Supplier Management System view_unit.php sql injection
A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/viewunit.php. The manipulation of the argument chkId[] leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14664?
CVE-2025-14664 has been classified as a critical severity vulnerability due to its potential for remote exploitation and SQL injection.
How do I fix CVE-2025-14664?
To mitigate CVE-2025-14664, sanitize all input parameters to prevent SQL injection attacks and apply the latest security patches from Campcodes.
What systems are affected by CVE-2025-14664?
CVE-2025-14664 specifically affects Campcodes Supplier Management System version 1.0.
Can CVE-2025-14664 lead to data loss?
Yes, if exploited, CVE-2025-14664 can potentially allow attackers to manipulate the database and lead to data loss or corruption.
Is remote exploitation possible with CVE-2025-14664?
Yes, remote exploitation of CVE-2025-14664 is possible, posing a significant risk to vulnerable systems.