Junglewise Threat Intelligence

CVE-2026-5561: Campcodes Complete POS Management and Inventory System RCE via configuration injection

CVE-2026-5561 · Severity: medium · CVSS 6.3 · Published 2026-04-05

Executive brief

A vulnerability in the Campcodes Complete POS Management and Inventory System allows an authenticated user to take control of the server. By manipulating system settings, an attacker can inject malicious commands that are executed when the system performs a database backup. This could lead to a total system compromise, theft of customer data, or disruption of business operations.

Technical details

The vulnerability exists in the Environment Variable Handler within app/Http/Controllers/SettingsController.php. The application fails to sanitize user input (specifically newline characters) when updating system configurations, allowing an authenticated attacker to inject arbitrary variables into the .env file. By overriding the DUMP_PATH variable, an attacker can redirect the path used by the DatabaseBackUp command. When a backup is triggered, the application executes the attacker-controlled path via PHP's exec() function, leading to Remote Code Execution (RCE) with the privileges of the web server.

Affected products

  • Campcodes Complete POS Management and Inventory System up to 4.0.6

Timeline

  • 2026-04-05: disclosed: Vulnerability disclosed and CVE assigned
  • 2026-04-05: advisory: NVD and VulDB published advisories

References