Unknown · Phpgurukul Online Shopping Portal · CVE-2025-1855
**Name of the Vulnerable Software and Affected Versions**
PHPGurukul Online Shopping Portal version 2.1
**Description**
A critical issue has been identified in the PHPGurukul Online Shopping Portal, affecting an unknown functionality of the file /product-details.php. The manipulation of the `quality`, `price`, `value`, `name`, `summary`, or `review` arguments leads to SQL injection. This issue can be exploited remotely.
**Recommendations**
For PHPGurukul Online Shopping Portal version 2.1, consider restricting access to the /product-details.php file until a patch is available. As a temporary workaround, avoid using the `quality`, `price`, `value`, `name`, `summary`, or `review` arguments in the affected file to minimize the risk of exploitation.