CVE-2025-1855: PHPGurukul Online Shopping Portal product-details.php sql injection
A vulnerability was found in PHPGurukul Online Shopping Portal 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /product-details.php. The manipulation of the argument quality/price/value/name/summary/review leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1855?
CVE-2025-1855 has been categorized as critical.
How do I fix CVE-2025-1855?
To mitigate CVE-2025-1855, ensure that input validation and parameterized queries are implemented in the affected file /product-details.php.
What type of vulnerability is CVE-2025-1855?
CVE-2025-1855 is an SQL injection vulnerability affecting the PHPGurukul Online Shopping Portal.
What are the components affected by CVE-2025-1855?
The vulnerability affects the manipulation of arguments such as quality, price, value, name, summary, and review in the file /product-details.php.
Who is affected by CVE-2025-1855?
Any user or administrator using PHPGurukul Online Shopping Portal version 2.1 is vulnerable to CVE-2025-1855.