CVE-2025-13554
Last modified
CVE-2025-13554 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. Such manipulation of the argument txtUsername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Campcodes | Supplier Management System | 1.0 |
References
- https://github.com/arpcyber060/CVE/issues/3Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.333321Permissions Required, VDB Entry
- https://vuldb.com/?id.333321Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.696515Third Party Advisory, VDB Entry
- https://www.campcodes.com/Product
- https://github.com/arpcyber060/CVE/issues/3Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-13554?
How severe is CVE-2025-13554?
How do I fix CVE-2025-13554?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13549A vulnerability was found in D-Link DIR-822K 1.00. This issu…8.8
- CVE-2025-1355A vulnerability was found in needyamin Library Card System 1…9.8
- CVE-2025-13550A vulnerability was determined in D-Link DIR-822K and DWR-M9…8.8
- CVE-2025-13551A vulnerability was identified in D-Link DIR-822K and DWR-M9…8.8
- CVE-2025-13552A security flaw has been discovered in D-Link DIR-822K and D…8.8
- CVE-2025-13553A weakness has been identified in D-Link DWR-M920 1.1.50. Th…8.8
- CVE-2025-13555A vulnerability was detected in Campcodes School File Manage…9.8
- CVE-2025-13556A flaw has been found in Campcodes Online Polling System 1.0…9.8
- CVE-2025-13557A vulnerability has been found in Campcodes Online Polling S…9.8
- CVE-2025-13558The Blog2Social: Social Media Auto Post & Scheduler plugin f…5.4
- CVE-2025-13559The EduKart Pro plugin for WordPress is vulnerable to Privil…9.8
- CVE-2025-1356A vulnerability was found in needyamin Library Card System 1…7.5
Are you affected by CVE-2025-13554?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
