Executive brief
A security vulnerability exists in the PHPGurukul Online Shopping Portal, a web application used for managing e-commerce operations. An attacker can exploit this flaw to interfere with the application's database, potentially leading to the exposure of customer information or unauthorized modification of order data. This could result in data theft, loss of customer trust, and disruption of business transactions.
Technical details
A SQL injection vulnerability exists in PHPGurukul Online Shopping Portal Project 2.1 within the '/cancelorder.php' component. The root cause is the improper sanitization of the 'oid' GET parameter before it is used in a database query. A remote attacker with low privileges (authenticated user) can provide a malicious payload, such as a time-based blind SQL injection string, to execute unauthorized SQL commands. This can lead to unauthorized data access, modification, or deletion. A public exploit (PoC) has been disclosed, and remediation involves implementing prepared statements with parameter binding.
Affected products
- PHPGurukul Online Shopping Portal Project 2.1
Timeline
- 2026-03-23: disclosed: Public issue opened on GitHub with PoC details
- 2026-04-06: advisory: CVE published and VulDB entry created