CVE-2025-7538: Unrestricted Upload in Campcodes Sales and Inventory System
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/product_update.php. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-7538: Unrestricted Upload in Campcodes Sales and Inventory System
Description
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/product_update.php. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-07-12T11:36:16.212Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 687405f7a83201eaacbdb1eb
Added to database: 7/13/2025, 7:16:07 PM
Last updated: 7/13/2025, 7:16:07 PM
Views: 1
Related Threats
CVE-2025-7537: SQL Injection in Campcodes Sales and Inventory System
MediumCVE-2025-7536: SQL Injection in Campcodes Sales and Inventory System
MediumCVE-2025-7535: SQL Injection in Campcodes Sales and Inventory System
MediumCVE-2025-7534: SQL Injection in PHPGurukul Student Result Management System
MediumCVE-2025-7533: SQL Injection in code-projects Job Diary
MediumActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.