Description
A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown function of the file /admin/adminHome.php. The manipulation of the argument social_insta leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
Published: 2026-06-04
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in an undisclosed function of adminHome.php lets an attacker manipulate the social_insta argument to craft a SQL injection. The vulnerability allows remote execution of arbitrary SQL statements, which can expose, alter, or delete sensitive data from the underlying database. The impact is confined to the database accessed by the application, but the malicious queries could provide the adversary with read or write privileges over stored information.

Affected Systems

The affected product is projectworlds Online Art Gallery Shop Project version 1.0. The vulnerability resides in the back‑end code of the /admin/adminHome.php page, a management interface used by site administrators.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and no EPSS value is published, so the current exploitation probability is unknown. The vulnerability is not listed in CISA KEV, suggesting no large‑scale coordinated exploitation yet. Inferred from the description, the attack vector is remote; an attacker can send a crafted request to the admin endpoint and trigger the injection. Successful exploitation could allow an attacker to gain unauthorized database access and potentially elevate privileges within the application.

Generated by OpenCVE AI on June 5, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact projectworlds to obtain an updated version of the Online Art Gallery Shop Project that removes the vulnerable code or applies a fix
  • If a patch is unavailable, restrict access to the /admin directory to localhost or a trusted network segment, and enforce strong authentication before allowing requests to adminHome.php
  • Validate and sanitize all incoming parameters, especially social_insta, using whitelisting or prepared statements to prevent SQL injection
  • Deploy a Web Application Firewall that blocks anomalous SQL patterns and monitor admin traffic for suspicious activity

Generated by OpenCVE AI on June 5, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Projectworlds online Art Gallery Shop
Vendors & Products Projectworlds online Art Gallery Shop

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown function of the file /admin/adminHome.php. The manipulation of the argument social_insta leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
Title projectworlds Online Art Gallery Shop Project adminHome.php sql injection
First Time appeared Projectworlds
Projectworlds online Art Gallery Shop Project
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:projectworlds:online_art_gallery_shop_project:*:*:*:*:*:*:*:*
Vendors & Products Projectworlds
Projectworlds online Art Gallery Shop Project
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Projectworlds Online Art Gallery Shop Online Art Gallery Shop Project
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-04T22:45:10.536Z

Reserved: 2026-06-04T15:34:39.819Z

Link: CVE-2026-10874

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T23:16:49.023

Modified: 2026-06-04T23:16:49.023

Link: CVE-2026-10874

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T07:30:30Z

Weaknesses