CVE-2026-5560: PHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injection
A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /payment-method.php of the component Parameter Handler. Performing a manipulation of the argument paymethod results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5560?
CVE-2026-5560 has a medium severity rating due to the potential for SQL injection attacks.
How do I fix CVE-2026-5560?
To fix CVE-2026-5560, sanitize all user inputs in the payment-method.php file to prevent SQL injection.
What impact does CVE-2026-5560 have on the PHPGurukul Online Shopping Portal Project?
CVE-2026-5560 could allow attackers to manipulate database queries, compromising the security of sensitive information.
Which versions of the PHPGurukul Online Shopping Portal Project are affected by CVE-2026-5560?
CVE-2026-5560 specifically affects PHPGurukul Online Shopping Portal Project version 2.1.
Is CVE-2026-5560 widely exploitable?
Yes, CVE-2026-5560 is widely exploitable, making it critical for users to apply necessary security precautions.