A vulnerability has been found in Campcodes Supplier Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view_unit.php. The manipulation of the argument chkId[] leads to sql injection. This vulnerability is referenced as CVE-2025-14664. Remote exploitation of the attack is possible.... Weiterlesen: CVE-2025-14664 | Campcodes Supplier Management System 1.0 /admin/view…
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2025-14664 | Campcodes Supplier Management System 1.0 /admin/view_unit.php chkId[] sql injection (EUVD-2025-203301)
A vulnerability has been found in Campcodes Supplier Management System 1.0 and classified as critical. This issue affects some unknown processing of the file…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
NVD Primärbewertung & CISA SSVCCVE-2025-14664
NVD: AnalyzedNVD 9.8 · CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD-Datenstand: 28.09.2026, 10:10 UTC
Ausnutzung beobachtet: Public PoC Automatisierbar: Ja Technischer Impact: Total
CISA-SSVC-Triage (vulnrichment)CVE-2025-14664
Exploitation: poc (PoC verfügbar)Automatable: yes (Automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2025-12-15T20:46:23.920520Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Web Referencewww.campcodes.com