SQL Injection Vulnerability in PHPGurukul Online Shopping Portal
CVE-2024-44659
9.8CRITICAL
What is CVE-2024-44659?
The PHPGurukul Online Shopping Portal version 2.0 contains a vulnerability that allows SQL injection through the 'email' parameter in the forgot-password.php file. This security flaw could potentially allow attackers to manipulate the database and access sensitive user data, posing a significant risk to the integrity of the application. Website administrators are urged to apply necessary patches and validate inputs to mitigate this vulnerability.
