A vulnerability classified as critical was found in Campcodes Online Shopping System 1.0. This impacts an unknown function of the file /login.php. Such manipulation of the argument Password leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-9691. The attack can be launched remotely. Moreover, an exploit is present.