CVE-2025-13423 Details
Description
A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.
A critical unrestricted file upload vulnerability has been identified in Campcodes Retro Basketball Shoes Online Store version 1.0. The issue resides in the admin_product.php file, where the product_image argument can be manipulated to bypass file type and content validation. This vulnerability allows remote attackers to upload malicious PHP scripts, such as web shells, which can be used to gain full control over the affected system by executing commands, accessing the file system, and stealing sensitive information.
It is recommended to implement proper file upload validation by whitelisting allowed file types, verifying MIME types, and inspecting file contents to detect executable scripts. Additionally, uploaded files should be stored in a non-web-accessible directory with execution permissions disabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Abxery/cveee/issues/6 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://github.com/Abxery/cveee/issues/6 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://vuldb.com/?ctiid.332945 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.332945 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.696051 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.campcodes.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| campcodes retro basketball shoes online store | 1.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Feb 24, 2026 | CVE Modified | [email protected] |
| Nov 21, 2025 | Initial Analysis | [email protected] |
| Nov 20, 2025 | CVE Modified | CISA-ADP |
| Nov 20, 2025 | New CVE Received | [email protected] |