CVE-2025-13411

Source
https://cve.org/CVERecord?id=CVE-2025-13411
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13411.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-13411
Published
2025-11-19T21:15:49.813Z
Modified
2026-03-15T22:50:15.662525Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/adminfootball.php. Performing a manipulation of the argument productimage results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13411.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.0"
            }
        ]
    }
]