CNNVD-202512-3444 Information

CNNVD ID

CNNVD-202512-3444

CVE-2025-14877

  • CNNVD Published: 2025-12-18

Description (Chinese)

CampCodes Supplier Management System是CampCodes公司的一个供应商管理系统。 Campcodes Supplier Management System 1.0版本存在SQL注入漏洞,该漏洞源于文件/admin/add_retailer.php中参数cmbAreaCode处理不当,可能导致SQL注入。

Description (English)

CampCodes Supplier Management System is a supplier management system for CampCodes. The version 1.0 of Campcodes Supplier Management System contains an injection loophole in SQL, which arises from the mishandling of the parameters cmbAreaCode in the document/admin/add retailer.php, which may lead to SQL injection.

Hazard Level

Medium

Vulnerability Type

SQL注入

Affected Vendor

CampCodes

Published

2025-12-18

Last Modified

2026-02-24

References

https://github.com/ProgramShowMaker/CVE/issues/6 https://vuldb.com/?ctiid.337368 https://vuldb.com/?id.337368 https://vuldb.com/?submit.715326 https://www.campcodes.com/

Share on: