Description
A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing manipulation of the argument product_image results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2025-11-19: | Advisory disclosed |
| 2025-11-19: | VulDB entry created |
| 2025-11-19: | VulDB entry last update |
Credits
laosiji (VulDB User)
References
vuldb.com/?id.332938 (VDB-332938 | Campcodes Retro Basketball Shoes Online Store admin_football.php unrestricted upload)
vuldb.com/?ctiid.332938 (VDB-332938 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.693697 (Submit #693697 | campcodes Retro Basketball Shoes Online Store V1.0 Unrestricted Upload)
github.com/laosijivul/cve/issues/2
www.campcodes.com/