SQL Injection Vulnerability in PHPGurukul Online Shopping Portal
CVE-2024-44659

9.8CRITICAL

Key Information:

Vendor

PHPGurukul

Vendor
CVE Published:
17 November 2025

What is CVE-2024-44659?

The PHPGurukul Online Shopping Portal version 2.0 contains a vulnerability that allows SQL injection through the 'email' parameter in the forgot-password.php file. This security flaw could potentially allow attackers to manipulate the database and access sensitive user data, posing a significant risk to the integrity of the application. Website administrators are urged to apply necessary patches and validate inputs to mitigate this vulnerability.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-44659 : SQL Injection Vulnerability in PHPGurukul Online Shopping Portal