CVE-2026-5561: Campcodes Complete POS Management and Inventory System Environment Variable SettingsController.php injection
A vulnerability was determined in Campcodes Complete POS Management and Inventory System up to 4.0.6. This affects an unknown function of the file app/Http/Controllers/SettingsController.php of the component Environment Variable Handler. Executing a manipulation can lead to injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5561?
CVE-2026-5561 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-5561?
To fix CVE-2026-5561, update Campcodes Complete POS Management and Inventory System to version 4.0.7 or later.
What systems are affected by CVE-2026-5561?
CVE-2026-5561 affects the Campcodes Complete POS Management and Inventory System versions up to and including 4.0.6.
What type of vulnerability is CVE-2026-5561?
CVE-2026-5561 is an environment variable injection vulnerability found in the SettingsController.php file.
Can CVE-2026-5561 be exploited remotely?
Yes, CVE-2026-5561 can be exploited remotely, allowing attackers to execute arbitrary code.