PT-2026-46408 · Projectworlds · Online Art Gallery Shop Project

·

CVE-2026-10874

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions projectworlds Online Art Gallery Shop Project version 1.0
Description Remote SQL injection is possible through the manipulation of the social insta argument within an unknown function in the '/admin/adminHome.php' endpoint. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations Update projectworlds Online Art Gallery Shop Project version 1.0 to a version that contains a fix for this issue. As a temporary mitigation, restrict access to the '/admin/adminHome.php' endpoint or avoid using the social insta argument.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10874

Affected Products

Online Art Gallery Shop Project