CVE-2025-13412
LOWCampcodes Retro Basketball Shoes Online Store - Code Injection
Title source: ruleDescription
A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing a manipulation of the argument product_name can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
References (5)
Scores
CVSS v3
2.4
EPSS
0.0004
EPSS Percentile
13.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
Classification
CWE
CWE-94
CWE-79
Status
published
Affected Products (1)
campcodes/retro_basketball_shoes_online_store
Timeline
Published
Nov 19, 2025
Tracked Since
Feb 18, 2026