CVE-2025-5032: Campcodes Online Shopping Portal edit-category.php sql injection
Published May 21, 2025
·Updated
A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/edit-category.php. The manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Campcodes Online Shopping Portal
Campcodes Online Shopping Portal=1.0
Event History
May 21, 2025
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Aug 14, 57378
Event
via FIRST·08:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5032?
CVE-2025-5032 is classified as a critical severity vulnerability.
2
What types of attacks can be executed through CVE-2025-5032?
CVE-2025-5032 allows for SQL injection attacks that can be launched remotely.
3
How do I fix CVE-2025-5032?
To fix CVE-2025-5032, sanitize and validate input in the /admin/edit-category.php file to prevent SQL injection.
4
Which software is affected by CVE-2025-5032?
CVE-2025-5032 affects Campcodes Online Shopping Portal version 1.0.
5
Where is the vulnerability location in the code for CVE-2025-5032?
The vulnerability in CVE-2025-5032 is located in the /admin/edit-category.php file.