A vulnerability, which was classified as critical, was found in Campcodes Computer Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/us_transac.php?action=add. Executing manipulation of the argument Username can lead to sql injection.

This vulnerability appears as CVE-2025-10445. The attack may be performed from remote. In addition, an exploit is available.