CVE-2026-5640: falha de média gravidade em PHPGurukul Online Shopping Portal Project
PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection
Publicada em
33Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 5.3epss 0.3%
probabilidade de exploração
0.3%top 77% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
PHPGurukul · Online Shopping Portal ProjectPoCs públicas encontradas — 1
cve_referencegithub.com/f1rstb100d/CVE/issues/18não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
CVEs relacionadas — PHPGurukul Online Shopping Portal Project
No mesmo produto, das mais perigosas para as menos.
CVE-2025-5367MEDIUMPHPGurukul Online Shopping Portal Project category.php sql injectionEPSS 0.5%CVE-2025-9013MEDIUMPHPGurukul Online Shopping Portal Project password-recovery.php sql injectionEPSS 0.4%CVE-2025-9012MEDIUMPHPGurukul Online Shopping Portal Project bill-ship-addresses.php sql injectionEPSS 0.4%CVE-2025-9011MEDIUMPHPGurukul Online Shopping Portal Project signup.php sql injectionEPSS 0.4%CVE-2026-5641MEDIUMPHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injectionEPSS 0.3%CVE-2026-5639MEDIUMPHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injectionEPSS 0.3%