Impact
The SQL injection vulnerability resides in PHPGurukul Online Shopping Portal Project version 2.1, specifically in the /admin/update-image2.php script. An attacker who can control the filename parameter can inject arbitrary SQL statements through the Parameter Handler. This flaw is aligned with CWE‑89 and CWE‑74 and enables unauthorized database access or manipulation, potentially compromising application data integrity and confidentiality.
Affected Systems
The vulnerability affects the PHPGurukul Online Shopping Portal Project, version 2.1. No other vendors or products are listed as impacted. The admin component that handles image updates is the target entry point.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is deemed moderate, and no EPSS data or KEV listing is available. However, the attack is remotely exploitable via HTTP requests to the admin script, and a public exploit is already available, implying that an attacker with network access could obtain or alter database contents without authentication, so proactive mitigation is advised.
OpenCVE Enrichment