CVE-2025-4930: Campcodes Online Shopping Portal my-cart.php sql injection
Published May 19, 2025
·Updated
A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /my-cart.php. The manipulation of the argument billingaddress leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Campcodes Online Shopping Portal
Campcodes Online Shopping Portal=1.0
Event History
May 19, 2025
CVE Published
via MITRE·11:31 AM
Data Sourced
via MITRE·11:31 AM
DescriptionSeverityWeakness
Sep 1, 57367
Event
via FIRST·10:29 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-4930?
CVE-2025-4930 is classified as a critical vulnerability.
2
How do I fix CVE-2025-4930?
To fix CVE-2025-4930, sanitize and validate all inputs to the /my-cart.php file to prevent SQL injection attacks.
3
What type of vulnerability is CVE-2025-4930?
CVE-2025-4930 is an SQL injection vulnerability.
4
Which software is affected by CVE-2025-4930?
CVE-2025-4930 affects Campcodes Online Shopping Portal version 1.0.
5
Can CVE-2025-4930 be exploited remotely?
Yes, CVE-2025-4930 can be exploited remotely.