CVE-2025-7538 Details
Description
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/product_update.php. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
A critical vulnerability allowing unrestricted file uploads has been identified in Campcodes Sales and Inventory System version 1.0. The issue resides in the file '/pages/product_update.php', where insufficient validation of the 'image' parameter permits attackers to upload malicious PHP scripts. This vulnerability can be exploited remotely, without any authentication, potentially leading to unauthorized control of the server and causing it to crash.
It is recommended to implement file type validation, checking both MIME types and file extensions against an allowlist of permitted types. Additionally, file size should be restricted to prevent denial-of-service attacks through large uploads. Uploaded files should be renamed to avoid using user-supplied names, and script execution should be disabled in the upload directory.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zhaodaojie/cve/issues/1 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://github.com/zhaodaojie/cve/issues/1 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://vuldb.com/?ctiid.316234 | [email protected] | Permissions Required |
| https://vuldb.com/?id.316234 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.613625 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.campcodes.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| campcodes sales and inventory system | 1.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jul 16, 2025 | Initial Analysis | [email protected] |
| Jul 14, 2025 | CVE Modified | CISA-ADP |
| Jul 13, 2025 | New CVE Received | [email protected] |