Executive brief
A security vulnerability exists in the projectworlds Online Art Gallery Shop Project, a web application used for managing and selling art online. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of customer information, tampering with gallery data, or disrupting the website's operations. This issue is particularly serious because a public exploit has already been released.
Technical details
A SQL injection vulnerability exists in projectworlds Online Art Gallery Shop Project 1.0 within the '/admin/adminHome.php' file. The root cause is the failure to sanitize or validate the 'social_twitter' POST parameter before using it in a database query. A remote attacker with low privileges (or potentially unauthenticated access depending on the environment) can use boolean-based, error-based, or time-based blind SQL injection techniques to extract sensitive data, modify database records, or achieve full system control. A public exploit (PoC) using sqlmap has been released. Mitigation involves implementing prepared statements with parameterized queries and strict input validation.
Affected products
- projectworlds Online Art Gallery Shop Project 1.0
Timeline
- 2026-05-17: disclosed: Vulnerability details and PoC shared on GitHub.
- 2026-06-04: advisory: CVE-2026-10875 published.