Junglewise Threat Intelligence

CVE-2026-5560: PHPGurukul Online Shopping Portal SQL injection in payment-method.php

CVE-2026-5560 · Severity: medium · CVSS 6.3 · Published 2026-04-05

Technologies: Phpgurukul Online Shopping Portal Project. Vendors: Phpgurukul.

Executive brief

A security vulnerability exists in the PHPGurukul Online Shopping Portal, an e-commerce platform. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of customer information or the disruption of store operations. This issue specifically affects the payment selection process during checkout.

Technical details

A SQL injection vulnerability exists in PHPGurukul Online Shopping Portal Project 2.1 within the '/payment-method.php' file. The root cause is the 'Parameter Handler' component's failure to properly sanitize the 'paymethod' POST argument before using it in a database query. A remote attacker with low privileges (authenticated user) can submit a crafted payload, such as a time-based blind SQL injection string, to execute unauthorized SQL commands. This can lead to full database compromise, including sensitive data extraction and data modification. A public exploit (PoC) has been disclosed.

Affected products

  • PHPGurukul Online Shopping Portal Project 2.1

Timeline

  • 2026-03-19: disclosed: Initial disclosure on GitHub by f1rstb100d
  • 2026-04-05: advisory: CVE published and VulDB entry created

References

Related threats