CVE-2026-5640: fallo de gravedad media en PHPGurukul Online Shopping Portal Project
PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection
Publicada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.3%
probabilidad de explotación
0.3%top 77% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
PHPGurukul · Online Shopping Portal ProjectPoCs públicas encontradas — 1
cve_referencegithub.com/f1rstb100d/CVE/issues/18no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — PHPGurukul Online Shopping Portal Project
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-5367MEDIUMPHPGurukul Online Shopping Portal Project category.php sql injectionEPSS 0.5%CVE-2025-9013MEDIUMPHPGurukul Online Shopping Portal Project password-recovery.php sql injectionEPSS 0.4%CVE-2025-9012MEDIUMPHPGurukul Online Shopping Portal Project bill-ship-addresses.php sql injectionEPSS 0.4%CVE-2025-9011MEDIUMPHPGurukul Online Shopping Portal Project signup.php sql injectionEPSS 0.4%CVE-2026-5641MEDIUMPHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injectionEPSS 0.3%CVE-2026-5639MEDIUMPHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injectionEPSS 0.3%