PT-2025-47529 · Campcodes · Campcodes Retro Basketball Shoes Online Store

·

CVE-2025-13410

·

Published

2025-11-19

·

Updated

2025-11-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Campcodes Retro Basketball Shoes Online Store version 1.0
Description A SQL injection issue exists in Campcodes Retro Basketball Shoes Online Store version 1.0. The issue is related to the manipulation of the tid parameter within an unknown function of the /admin/receipt.php file. This allows for remote execution of attacks. The exploit is publicly available. The vulnerability impacts the admin interface, which is frequently targeted by credential stuffing attempts. This issue falls within the scope of PCI DSS due to the potential exposure of payment card data, Personally Identifiable Information (PII), and order history. Access to payment data could necessitate forensic investigation and card reissuance.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13410

Affected Products

Campcodes Retro Basketball Shoes Online Store