SQL Injection Vulnerability in Campcodes Online Shopping Portal 1.0
CVE-2025-5078
Key Information:
- Vendor
Campcodes
- Status
- Vendor
- CVE Published:
- 22 May 2025
Badges
What is CVE-2025-5078?
A SQL injection vulnerability exists in the Campcodes Online Shopping Portal 1.0, specifically within the /admin/subcategory.php file. This security flaw arises when user input related to the 'Category' argument is not properly validated, enabling remote attackers to execute arbitrary SQL commands. The consequence of such exploitation can compromise the database integrity and potentially expose sensitive information. As the vulnerability has been publicly disclosed, it is crucial for users to apply necessary patches or modifications to mitigate potential threats. For more information and to safeguard your application, visit the official Campcodes website.
Affected Version(s)
Online Shopping Portal 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved