SQL Injection Vulnerability in PHPGurukul Online Shopping Portal
CVE-2025-26156
8.8HIGH
What is CVE-2025-26156?
A SQL Injection vulnerability exists in the PHPGurukul Online Shopping Portal version 2.1, located in the /shopping/track-orders.php file. This vulnerability enables remote attackers to manipulate database queries by injecting malicious SQL code through the orderid parameter in POST requests. Exploiting this flaw can lead to unauthorized access and execution of arbitrary code, posing significant risks to the security of the affected application and its users.