PT-2025-47529 · Campcodes · Campcodes Retro Basketball Shoes Online Store
Laosiji
·
Published
2025-11-19
·
Updated
2025-11-24
·
CVE-2025-13410
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Campcodes Retro Basketball Shoes Online Store version 1.0
Description
A SQL injection issue exists in Campcodes Retro Basketball Shoes Online Store version 1.0. The issue is related to the manipulation of the
tid parameter within an unknown function of the /admin/receipt.php file. This allows for remote execution of attacks. The exploit is publicly available. The vulnerability impacts the admin interface, which is frequently targeted by credential stuffing attempts. This issue falls within the scope of PCI DSS due to the potential exposure of payment card data, Personally Identifiable Information (PII), and order history. Access to payment data could necessitate forensic investigation and card reissuance.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Campcodes Retro Basketball Shoes Online Store