PT-2025-47529 · Campcodes · Campcodes Retro Basketball Shoes Online Store

Laosiji

·

Published

2025-11-19

·

Updated

2025-11-24

·

CVE-2025-13410

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Campcodes Retro Basketball Shoes Online Store version 1.0
Description A SQL injection issue exists in Campcodes Retro Basketball Shoes Online Store version 1.0. The issue is related to the manipulation of the tid parameter within an unknown function of the /admin/receipt.php file. This allows for remote execution of attacks. The exploit is publicly available. The vulnerability impacts the admin interface, which is frequently targeted by credential stuffing attempts. This issue falls within the scope of PCI DSS due to the potential exposure of payment card data, Personally Identifiable Information (PII), and order history. Access to payment data could necessitate forensic investigation and card reissuance.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-13410

Affected Products

Campcodes Retro Basketball Shoes Online Store