CVE-2026-3406: projectworlds Online Art Gallery Shop Registration registration.php sql injection
A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3406?
CVE-2026-3406 is considered a high severity vulnerability due to its potential for SQL injection that can lead to unauthorized access to the database.
How do I fix CVE-2026-3406?
To fix CVE-2026-3406, sanitize all user inputs in the registration.php file to prevent SQL injection attacks.
What are the potential impacts of CVE-2026-3406?
The potential impacts of CVE-2026-3406 include data leakage, unauthorized data manipulation, and complete system compromise.
Which versions of the Online Art Gallery Shop are affected by CVE-2026-3406?
CVE-2026-3406 affects the projectworlds Online Art Gallery Shop version 1.0.
Is CVE-2026-3406 easy to exploit?
Yes, CVE-2026-3406 is relatively easy to exploit, requiring minimal technical skills to perform the SQL injection.