---
id: CVE-2025-12338
title: >-
  A weakness has been identified in Campcodes Retro Basketball Shoes Online
  Store 1.0
summary: >-
  A weakness has been identified in Campcodes Retro Basketball Shoes Online
  Store 1.0. This vulnerability affects unknown code of the file
  /admin/admin_product.ph. Executing a manipulation of the argument pid can lead
  to sql injection. The…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: campcodes
product: retro_basketball_shoes_online_store
affected:
  - retro_basketball_shoes_online_store = 1.0
published: '2025-10-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12338'
references:
  - url: 'https://github.com/HYLCXH/CVE/issues/16'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.330125'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.330125'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.674492'
    label: cna@vuldb.com
  - url: 'https://www.campcodes.com/'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00463
epssPercentile: 0.38154
ingestedAt: '2026-10-08T11:31:27.657Z'
---

## Overview

A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file /admin/admin_product.ph. Executing a manipulation of the argument pid can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

## Affected

- `retro_basketball_shoes_online_store = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
