CVE-2025-8229: Campcodes Courier Management System parcel_list.php sql injection
Published Jul 27, 2025
·Updated
A vulnerability classified as critical has been found in Campcodes Courier Management System 1.0. This affects an unknown part of the file /parcellist.php. The manipulation of the argument s leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Campcodes Courier Management System
Campcodes Courier Management System=1.0
Event History
Jul 27, 2025
CVE Published
via MITRE·10:02 AM
Data Sourced
via MITRE·10:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 24, 58473
Event
via NVD·07:13 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-8229?
CVE-2025-8229 is classified as a critical vulnerability.
2
How do I fix CVE-2025-8229?
To fix CVE-2025-8229, it is crucial to sanitize and validate user inputs in the /parcel_list.php file to prevent SQL injection.
3
What type of attack does CVE-2025-8229 allow?
CVE-2025-8229 allows for a remote SQL injection attack through manipulation of the argument 's'.
4
Which software is affected by CVE-2025-8229?
CVE-2025-8229 affects Campcodes Courier Management System version 1.0.
5
Can CVE-2025-8229 be exploited remotely?
Yes, CVE-2025-8229 can be exploited remotely.