PT-2025-47202 · Phpgurukul · Phpgurukul Online Shopping Portal

Published

2025-11-17

·

Updated

2025-11-18

·

CVE-2024-44659

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Online Shopping Portal version 2.0
Description The PHPGurukul Online Shopping Portal 2.0 is susceptible to SQL Injection due to improper handling of the email parameter in the forgot-password.php script. Successful exploitation allows an attacker to execute arbitrary SQL code, potentially leading to data theft, data modification, or system compromise. SQL Injection (SQLi) is a code injection technique used to attack data-driven applications.
Recommendations Apply updates to address the handling of the email parameter in the forgot-password.php script.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-44659

Affected Products

Phpgurukul Online Shopping Portal