Description
A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Published: 2026-04-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

A flaw in the /admin/update-image3.php of PHPGurukul Online Shopping Portal Project 2.1 allows an attacker to manipulate the filename parameter, leading to unfiltered SQL injection that can be triggered remotely. This weakness may enable the execution of arbitrary SQL commands against the back‑end database, compromising data confidentiality and integrity. The vulnerability is tied to the Parameter Handler component and is classified as CWE-74 and CWE-89.

Affected Systems

The affected system is the PHPGurukul Online Shopping Portal Project, version 2.1. Users of this version who expose the admin update-image3.php endpoint are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk; EPSS data is unavailable and the vulnerability is not listed in KEV. Publicly available exploits demonstrate that the flaw can be abused from a remote network. The likely attack vector is a crafted HTTP request to the update-image3.php script with a malicious filename value. The exposure is limited to systems that host the vulnerable application and have the update-image3.php endpoint accessible.

Generated by OpenCVE AI on April 6, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑issued security patch for PHPGurukul Online Shopping Portal Project 2.1 or upgrade to a non‑vulnerable version.
  • Restrict access to the /admin/update-image3.php endpoint to authenticated administrators only, using appropriate firewall or web‑application‑level controls.
  • Modify the code to validate and sanitize the filename parameter and use parameterized SQL queries.

Generated by OpenCVE AI on April 6, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 07:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Apr 2026 09:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Title PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection
First Time appeared Phpgurukul
Phpgurukul online Shopping Portal Project
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:phpgurukul:online_shopping_portal_project:*:*:*:*:*:*:*:*
Vendors & Products Phpgurukul
Phpgurukul online Shopping Portal Project
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Phpgurukul Online Shopping Portal Project
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-07T03:04:46.001Z

Reserved: 2026-04-05T20:30:59.059Z

Link: CVE-2026-5639

cve-icon Vulnrichment

Updated: 2026-04-07T03:04:41.595Z

cve-icon NVD

Status : Deferred

Published: 2026-04-06T09:16:18.493

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-5639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-06T21:33:04Z

Weaknesses