CVE-2025-13412

LOW

Campcodes Retro Basketball Shoes Online Store - Code Injection

Title source: rule

Description

A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing a manipulation of the argument product_name can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 2.4
EPSS 0.0004
EPSS Percentile 13.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-94 CWE-79
Status published

Affected Products (1)

campcodes/retro_basketball_shoes_online_store

Timeline

Published Nov 19, 2025
Tracked Since Feb 18, 2026