PT-2026-30450 · Phpgurukul · Online Shopping Portal Project

F1Rstb100D

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5583

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
A security vulnerability has been detected in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /my-profile.php of the component Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5583

Affected Products

Online Shopping Portal Project