{"api_version":"1","generated_at":"2026-07-23T20:19:05+00:00","cve":"CVE-2023-3068","urls":{"html":"https://cve.report/CVE-2023-3068","api":"https://cve.report/api/cve/CVE-2023-3068.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-3068","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-3068"},"summary":{"title":"CVE-2023-3068","description":"A vulnerability classified as critical has been found in Campcodes Retro Cellphone Online Store 1.0. Affected is an unknown function of the file /admin/modal_add_product.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230580.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2023-06-02 16:15:00","updated_at":"2023-11-07 04:17:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://vuldb.com/?id.230580","name":"https://vuldb.com/?id.230580","refsource":"MISC","tags":[],"title":"CVE-2023-3068: Campcodes Retro Cellphone Online Store modal_add_product.php sql injection","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?ctiid.230580","name":"https://vuldb.com/?ctiid.230580","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://github.com/wordpress405/cve/blob/main/Retro%20Cellphone%20Online%20Store.pdf","name":"https://github.com/wordpress405/cve/blob/main/Retro%20Cellphone%20Online%20Store.pdf","refsource":"MISC","tags":[],"title":"cve/Retro Cellphone Online Store.pdf at main · wordpress405/cve · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-3068","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3068","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"3068","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"retro_cellphone_online_store_project","cpe5":"retro_cellphone_online_store","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-3068","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability classified as critical has been found in Campcodes Retro Cellphone Online Store 1.0. Affected is an unknown function of the file /admin/modal_add_product.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230580."},{"lang":"deu","value":"Es wurde eine kritische Schwachstelle in Campcodes Retro Cellphone Online Store 1.0 entdeckt. Es betrifft eine unbekannte Funktion der Datei /admin/modal_add_product.php. Durch das Beeinflussen des Arguments category mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-89 SQL Injection","cweId":"CWE-89"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Campcodes","product":{"product_data":[{"product_name":"Retro Cellphone Online Store","version":{"version_data":[{"version_affected":"=","version_value":"1.0"}]}}]}}]}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.230580","refsource":"MISC","name":"https://vuldb.com/?id.230580"},{"url":"https://vuldb.com/?ctiid.230580","refsource":"MISC","name":"https://vuldb.com/?ctiid.230580"},{"url":"https://github.com/wordpress405/cve/blob/main/Retro%20Cellphone%20Online%20Store.pdf","refsource":"MISC","name":"https://github.com/wordpress405/cve/blob/main/Retro%20Cellphone%20Online%20Store.pdf"}]},"credits":[{"lang":"en","value":"wenqifeng (VulDB User)"}],"impact":{"cvss":[{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"},{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"},{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}]}},"nvd":{"publishedDate":"2023-06-02 16:15:00","lastModifiedDate":"2023-11-07 04:17:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:retro_cellphone_online_store_project:retro_cellphone_online_store:1.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}