CVE-2025-5367: PHPGurukul Online Shopping Portal Project category.php sql injection
A vulnerability was found in PHPGurukul Online Shopping Portal Project 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument Product leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5367?
CVE-2025-5367 has been declared as critical due to its potential for remote SQL injection.
How do I fix CVE-2025-5367?
To fix CVE-2025-5367, you should validate and sanitize user inputs in the affected /category.php file to prevent SQL injection.
What type of vulnerability is CVE-2025-5367?
CVE-2025-5367 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Can CVE-2025-5367 be exploited remotely?
Yes, CVE-2025-5367 can be exploited remotely, making it critical for online security.
Which software is affected by CVE-2025-5367?
CVE-2025-5367 affects the PHPGurukul Online Shopping Portal Project version 1.0.