CVE-2025-6311: Campcodes Sales and Inventory System account_add.php sql injection
Published Jun 20, 2025
·Updated
A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /pages/accountadd.php. The manipulation of the argument id/amount leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Campcodes Sales and Inventory System
Campcodes Sales and Inventory System=1.0
Event History
Jun 20, 2025
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Jul 9, 57515
Event
via FIRST·12:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-6311?
The severity of CVE-2025-6311 is classified as critical.
2
What type of vulnerability is CVE-2025-6311?
CVE-2025-6311 is a SQL injection vulnerability.
3
How does CVE-2025-6311 impact the Campcodes Sales and Inventory System?
CVE-2025-6311 allows attackers to manipulate inputs, potentially leading to unauthorized access and data breaches.
4
How do I fix CVE-2025-6311?
To fix CVE-2025-6311, sanitize and validate all user inputs to prevent SQL injection.
5
Can CVE-2025-6311 be exploited remotely?
Yes, CVE-2025-6311 can be exploited remotely.