Description
A vulnerability was determined in Campcodes Complete POS Management and Inventory System up to 4.0.6. This affects an unknown function of the file app/Http/Controllers/SettingsController.php of the component Environment Variable Handler. Executing a manipulation can lead to injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
CVSS 6.3EPSS 0.291%Risk 0.65
View source- Published
- 2026-04-05 11:16:56
- Affected versions
- <=4.0.6
- Type
- Installed app
- Last modified
- 2026-07-24 20:10:00
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L