CVE-2025-12336: Campcodes Retro Basketball Shoes Online Store admin_index.php sql injection
A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/adminindex.php. Such manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12336?
CVE-2025-12336 has been classified as a high severity vulnerability due to its potential for SQL injection, which allows remote attackers to manipulate database queries.
How do I fix CVE-2025-12336?
To fix CVE-2025-12336, ensure that input sanitization and parameterized queries are implemented in the /admin/admin_index.php file to prevent SQL injection.
Who is affected by CVE-2025-12336?
CVE-2025-12336 affects users of the Campcodes Retro Basketball Shoes Online Store version 1.0 that utilize the vulnerable /admin/admin_index.php functionality.
Can CVE-2025-12336 be exploited remotely?
Yes, CVE-2025-12336 can be exploited remotely, allowing attackers to execute SQL injection attacks from outside the application.
What should I do if my system is vulnerable to CVE-2025-12336?
If your system is vulnerable to CVE-2025-12336, you should apply the recommended patches or implement security measures to protect against SQL injection.