Impact
A flaw in the /admin/update-image3.php of PHPGurukul Online Shopping Portal Project 2.1 allows an attacker to manipulate the filename parameter, leading to unfiltered SQL injection that can be triggered remotely. This weakness may enable the execution of arbitrary SQL commands against the back‑end database, compromising data confidentiality and integrity. The vulnerability is tied to the Parameter Handler component and is classified as CWE-74 and CWE-89.
Affected Systems
The affected system is the PHPGurukul Online Shopping Portal Project, version 2.1. Users of this version who expose the admin update-image3.php endpoint are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk; EPSS data is unavailable and the vulnerability is not listed in KEV. Publicly available exploits demonstrate that the flaw can be abused from a remote network. The likely attack vector is a crafted HTTP request to the update-image3.php script with a malicious filename value. The exposure is limited to systems that host the vulnerable application and have the update-image3.php endpoint accessible.
OpenCVE Enrichment