Junglewise Threat Intelligence

CVE-2026-5583: PHPGurukul Online Shopping Portal SQL injection in my-profile.php

CVE-2026-5583 · Severity: medium · CVSS 6.3 · Published 2026-04-05

Technologies: Phpgurukul Online Shopping Portal Project. Vendors: Phpgurukul.

Executive brief

A security vulnerability exists in the PHPGurukul Online Shopping Portal, a web application used for managing e-commerce storefronts. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of customer information or the disruption of the shopping service. This issue specifically affects the user profile management section of the site.

Technical details

A SQL injection vulnerability exists in PHPGurukul Online Shopping Portal Project 2.1 within the '/my-profile.php' file. The root cause is the improper neutralization of the 'fullname' POST parameter, which is used in SQL queries without sufficient sanitization or parameterization. A remote attacker with low privileges (authenticated user) can exploit this via time-based blind SQL injection techniques to execute arbitrary SQL commands. This can result in unauthorized data retrieval, modification, or deletion within the database. A public exploit (PoC) has been disclosed.

Affected products

  • PHPGurukul Online Shopping Portal Project 2.1

Timeline

  • 2026-03-20: disclosed: Public issue opened on GitHub with PoC details
  • 2026-04-05: advisory: CVE published by VulDB/NVD

References

Related threats