CVE-2025-13410: Campcodes Retro Basketball Shoes Online Store receipt.php sql injection
A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of the file /admin/receipt.php. Such manipulation of the argument tid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13410?
CVE-2025-13410 is classified as a high-severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-13410?
To fix CVE-2025-13410, sanitize and validate all user inputs in the /admin/receipt.php file to prevent SQL injection.
What type of vulnerability is CVE-2025-13410?
CVE-2025-13410 is an SQL injection vulnerability that can be exploited remotely by manipulating certain parameters.
Which software is affected by CVE-2025-13410?
The affected software is Campcodes Retro Basketball Shoes Online Store version 1.0.
Can CVE-2025-13410 be exploited remotely?
Yes, CVE-2025-13410 can be exploited remotely, allowing attackers to execute SQL injection attacks.