CVE-2025-14952: Campcodes Supplier Management System add_category.php sql injection
A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/addcategory.php. Performing a manipulation of the argument txtCategoryName results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14952?
CVE-2025-14952 is classified as a critical SQL injection vulnerability within Campcodes Supplier Management System 1.0.
How do I fix CVE-2025-14952?
To mitigate CVE-2025-14952, sanitize and validate the input for the txtCategoryName argument in the /admin/add_category.php file.
What are the possible impacts of CVE-2025-14952?
Exploitation of CVE-2025-14952 can lead to unauthorized database access and manipulation of sensitive information.
Who is affected by CVE-2025-14952?
CVE-2025-14952 affects users of Campcodes Supplier Management System version 1.0.
Can CVE-2025-14952 be exploited remotely?
Yes, CVE-2025-14952 can be exploited remotely, allowing attackers to perform SQL injection without physical access.