A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/add_distributor.php. This manipulation of the argument txtDistributorAddress causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
| Software | From | Fixed in |
|---|---|---|
| campcodes / supplier_management_system | 1.0 | 1.0.x |