CVE-2025-12338: Campcodes Retro Basketball Shoes Online Store admin_product.ph sql injection
A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file /admin/adminproduct.ph. Executing a manipulation of the argument pid can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12338?
CVE-2025-12338 is identified as a critical vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-12338?
To fix CVE-2025-12338, ensure that input validation is implemented for the 'pid' parameter in the /admin/admin_product.ph file.
What type of vulnerability is CVE-2025-12338?
CVE-2025-12338 is a SQL injection vulnerability that occurs due to inadequate input sanitization.
Who is affected by CVE-2025-12338?
CVE-2025-12338 affects users of the Campcodes Retro Basketball Shoes Online Store version 1.0.
Can CVE-2025-12338 be exploited remotely?
Yes, CVE-2025-12338 can be exploited remotely by manipulating the 'pid' parameter.