Junglewise Threat Intelligence

CVE-2026-10874: Projectworlds Online Art Gallery Shop Project SQL injection in adminHome.php

CVE-2026-10874 · Severity: medium · CVSS 6.3 · Published 2026-06-04

Technologies: Projectworlds Online Art Gallery Shop Project. Vendors: Projectworlds.

Executive brief

A vulnerability exists in the Online Art Gallery Shop Project, a web application used for managing and selling artwork online. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive customer information or the modification of site content. This could result in significant data loss, reputational damage, and loss of customer trust.

Technical details

A SQL injection vulnerability exists in Projectworlds Online Art Gallery Shop Project 1.0 within the /admin/adminHome.php component. The root cause is the improper neutralization of the 'social_insta' POST parameter, which is used directly in SQL queries without adequate validation or parameterized queries. A remote attacker with low privileges can exploit this via boolean-based, error-based, or time-based blind injection techniques. Successful exploitation allows for unauthorized database access, data exfiltration, and potential tampering with database records. While some reports suggest no authentication is required, the CVSS vector indicates low privileges (PR:L) are typically needed to access the admin component.

Affected products

  • Projectworlds Online Art Gallery Shop Project 1.0

Timeline

  • 2026-05-17: disclosed: Initial discovery and PoC shared on GitHub
  • 2026-06-04: advisory: CVE published to NVD dataset

References

Related threats