Vulnerability Description
A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/subcategory.php. Performing manipulation of the argument Category results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Campcodes | Online Shopping Portal | 1.0 |
| Phpgurukul | Online Shopping Portal | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/GeniusWang23/CVE/issues/2ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/?ctiid.309958Permissions RequiredVDB Entry
- https://vuldb.com/?id.309958Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.581432Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.641751Third Party AdvisoryVDB Entry
- https://github.com/GeniusWang23/CVE/issues/2ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2025-5078?
CVE-2025-5078 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/subcategory.php. Performing manipulation of the argument Category re...
How severe is CVE-2025-5078?
CVE-2025-5078 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-5078?
Check the references section above for vendor advisories and patch information. Affected products include: Campcodes Online Shopping Portal, Phpgurukul Online Shopping Portal.