SQL Injection Vulnerability in Campcodes Online Shopping Portal
CVE-2025-4930
Key Information:
- Vendor
Campcodes
- Status
- Vendor
- CVE Published:
- 19 May 2025
Badges
What is CVE-2025-4930?
A SQL injection vulnerability has been identified in the Campcodes Online Shopping Portal, specifically within the /my-cart.php file due to improper handling of the 'billingaddress' argument. This flaw allows attackers to execute arbitrary SQL queries, potentially compromising the database and gaining unauthorized access to sensitive data. The issue has been disclosed publicly, raising concerns for users as remote exploits are possible. Administrators are advised to implement security patches and mitigate this vulnerability to safeguard their applications.
Affected Version(s)
Online Shopping Portal 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved