A vulnerability was found in Campcodes Computer Sales and Inventory System 1.0. It has been declared as critical. The affected element is an unknown function of the file /pages/cust_edit1.php. The manipulation of the argument ID results in sql injection.

This vulnerability was named CVE-2025-10435. The attack may be performed from remote. In addition, an exploit is available.