CVE-2025-10417
15.09.2025, 01:15
A security flaw has been discovered in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function of the file /ajax.php?action=delete_product. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
| Vendor | Product | Version | 
|---|---|---|
| campcodes | grocery_sales_and_inventory_system | 1.0 | 
𝑥
= Vulnerable software versions