Unknown · Campcodes Online Shopping Portal · CVE-2025-4875
Name of the Vulnerable Software and Affected Versions:
Campcodes Online Shopping Portal version 1.0
Description:
A critical issue has been identified, affecting the /forgot-password.php file, where manipulation of the `email` argument leads to SQL injection. This can be initiated remotely.
Recommendations:
For Campcodes Online Shopping Portal version 1.0, consider restricting access to the /forgot-password.php file until a fix is available. As a temporary workaround, avoid using the `email` argument in the forgot password functionality to minimize the risk of exploitation.