CVE-2025-8254: Campcodes Courier Management System view_parcel.php sql injection
A vulnerability was found in Campcodes Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /viewparcel.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8254?
CVE-2025-8254 has been declared as a critical severity vulnerability.
How does CVE-2025-8254 affect the Campcodes Courier Management System?
CVE-2025-8254 affects the processing of user input in the /view_parcel.php file, leading to SQL injection vulnerabilities.
Can CVE-2025-8254 be exploited remotely?
Yes, CVE-2025-8254 can be exploited remotely, allowing attackers to execute malicious SQL commands.
What steps should be taken to mitigate CVE-2025-8254?
To mitigate CVE-2025-8254, input validation and prepared statements should be implemented to prevent SQL injection.
Who is affected by CVE-2025-8254?
Users of the Campcodes Courier Management System version 1.0 are affected by CVE-2025-8254.