CVE-2025-9011: PHPGurukul Online Shopping Portal Project signup.php sql injection
A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/signup.php. The manipulation of the argument emailid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9011?
CVE-2025-9011 is classified as a critical vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-9011?
To fix CVE-2025-9011, validate and sanitize user input in the emailid argument of the signup.php file to prevent SQL injection.
What software is affected by CVE-2025-9011?
CVE-2025-9011 affects the PHPGurukul Online Shopping Portal Project version 2.0.
Can CVE-2025-9011 be exploited remotely?
Yes, CVE-2025-9011 can be exploited remotely, allowing attackers to execute malicious SQL queries.
What impact does CVE-2025-9011 have on data security?
CVE-2025-9011 can lead to unauthorized access to sensitive data within the application's database.