Back

MEDIUM

Campcodes Supplier Management System edit_profile.php sql injection

Published Jan 5, 2026

Description

A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality of the file /retailer/edit_profile.php. This manipulation of the argument txtRetailerAddress causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulDB
Published Jan 5, 2026
Updated Feb 23, 2026
Reserved Jan 5, 2026

CISA Vulnrichment

Updated Jan 5, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulDB
Published Jan 5, 2026
Updated Feb 23, 2026

GitHub

No data