📦 Sales And Inventory System

by Campcodes

🔍 What is Sales And Inventory System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-7933

HIGH CVSS 7.3 Jul 21, 2025

A critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /pages/settings_update.php file...

CVE-2025-7537

HIGH CVSS 7.3 Jul 13, 2025

A critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in /pages/product_update.php. This aff...

CVE-2025-7535

HIGH CVSS 7.3 Jul 13, 2025

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'sid' parameter in the /pages/reprint_cash.php f...

CVE-2025-7469

HIGH CVSS 7.3 Jul 12, 2025

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via the prod_name parameter in the product_add.php file....

CVE-2025-7183

HIGH CVSS 7.3 Jul 8, 2025

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows attackers to execute arbitrary SQL commands through the Customer parameter in /pages/customer_account.php. ...

CVE-2025-6313

HIGH CVSS 7.3 Jun 20, 2025

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows attackers to execute arbitrary SQL commands via the Category parameter in /pages/cat_add.php. Remote attack...

CVE-2025-6311

HIGH CVSS 7.3 Jun 20, 2025

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via the id/amount parameters in the /pages/account_add.p...

CVE-2025-4899

HIGH CVSS 7.3 May 18, 2025

CVE-2025-4899 is a critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ID parameter in /pages/transa...

CVE-2025-4885

HIGH CVSS 7.3 May 18, 2025

A critical SQL injection vulnerability in itsourcecode Sales and Inventory System 1.0 allows attackers to execute arbitrary SQL commands via the 'serial' parameter in the product_add.php file. This af...

CVE-2025-4815

HIGH CVSS 7.3 May 17, 2025

Campcodes Sales and Inventory System 1.0 contains a critical SQL injection vulnerability in the supplier_update.php file that allows remote attackers to execute arbitrary SQL commands by manipulating ...

CVE-2025-4746

HIGH CVSS 7.3 May 16, 2025

Campcodes Sales and Inventory System 1.0 contains a critical SQL injection vulnerability in the purchase_delete.php file that allows remote attackers to execute arbitrary SQL commands by manipulating ...

CVE-2025-4741

HIGH CVSS 7.3 May 16, 2025

Campcodes Sales and Inventory System 1.0 contains a critical SQL injection vulnerability in the /pages/purchase_add.php file that allows remote attackers to manipulate database queries via the ID para...

CVE-2025-4718

HIGH CVSS 7.3 May 15, 2025

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows attackers to execute arbitrary SQL commands via the 'last' parameter in the customer_add.php file. Remote a...

CVE-2025-4716

HIGH CVSS 7.3 May 15, 2025

Campcodes Sales and Inventory System 1.0 contains a critical SQL injection vulnerability in the /pages/credit_transaction_add.php file via the prod_name parameter. This allows remote attackers to exec...

CVE-2025-4713

HIGH CVSS 7.3 May 15, 2025

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'sid' parameter in /pages/print.php. Attackers c...

CVE-2025-4709

HIGH CVSS 7.3 May 15, 2025

A critical SQL injection vulnerability exists in Campcodes Sales and Inventory System 1.0, specifically in the /pages/transaction_del.php file's ID parameter. Attackers can remotely execute arbitrary ...

CVE-2025-4711

HIGH CVSS 7.3 May 15, 2025

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via the prod_name parameter in the /pages/stockin_add.ph...

CVE-2025-4708

HIGH CVSS 7.3 May 15, 2025

A critical SQL injection vulnerability exists in Campcodes Sales and Inventory System 1.0, specifically in the discount parameter of the /pages/sales_add.php file. This allows remote attackers to exec...

CVE-2025-4503

HIGH CVSS 7.3 May 10, 2025

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to manipulate database queries via the ID parameter in customer_update.php. Attackers can ...

CVE-2025-9922

MEDIUM CVSS 4.3 Sep 3, 2025

Campcodes Sales and Inventory System 1.0 contains a cross-site scripting (XSS) vulnerability in the /index.php file's page parameter. Attackers can inject malicious scripts that execute in users' brow...

CVE-2025-4735

MEDIUM CVSS 6.3 May 16, 2025

CVE-2025-4735 is a critical unrestricted file upload vulnerability in Campcodes Sales and Inventory System 1.0. Attackers can remotely upload malicious files via the Picture parameter in /pages/produc...