CVE-2026-0597: Campcodes Supplier Management System edit_profile.php sql injection
A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality of the file /retailer/edit_profile.php. This manipulation of the argument txtRetailerAddress causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0597?
CVE-2026-0597 is classified as a high-severity vulnerability due to its potential for remote SQL injection exploitation.
How do I fix CVE-2026-0597?
To fix CVE-2026-0597, sanitize and validate all user inputs, especially in the affected file /retailer/edit_profile.php.
What is the impact of CVE-2026-0597?
The impact of CVE-2026-0597 includes unauthorized access to the database, data manipulation, and potential data breaches.
Which version of Campcodes Supplier Management System is affected by CVE-2026-0597?
CVE-2026-0597 affects Campcodes Supplier Management System version 1.0.
Is remote exploitation possible with CVE-2026-0597?
Yes, remote exploitation is possible with CVE-2026-0597 due to the SQL injection vulnerability.