SQL Injection Vulnerability in PHPGurukul Online Shopping Portal
CVE-2025-26156
8.8HIGH
Summary
A SQL Injection vulnerability exists in the PHPGurukul Online Shopping Portal version 2.1, located in the /shopping/track-orders.php file. This vulnerability enables remote attackers to manipulate database queries by injecting malicious SQL code through the orderid parameter in POST requests. Exploiting this flaw can lead to unauthorized access and execution of arbitrary code, posing significant risks to the security of the affected application and its users.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved