CVE-2025-5059: Campcodes Online Shopping Portal edit-subcategory.php unrestricted upload
A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5059?
CVE-2025-5059 is classified as a critical vulnerability due to its potential for unrestricted file uploads.
How do I fix CVE-2025-5059?
To fix CVE-2025-5059, implement proper input validation and restrict uploads to specific file types and sizes.
What is affected by CVE-2025-5059?
CVE-2025-5059 affects the Campcodes Online Shopping Portal 1.0, particularly the /admin/edit-subcategory.php file.
What are the risks of not addressing CVE-2025-5059?
Failing to address CVE-2025-5059 may lead to unauthorized access, data breaches, or malicious code execution on the server.
Is there a public exploit available for CVE-2025-5059?
Currently, there is no specific public exploit reported for CVE-2025-5059, but the nature of the vulnerability indicates a high risk for exploitation.