CVE-2026-5606: PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injection
A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /order-details.php of the component Parameter Handler. The manipulation of the argument orderid results in sql injection. It is possible to launch the attack remotely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5606?
CVE-2026-5606 has been classified with a medium severity level due to its potential for SQL Injection exploits.
How do I fix CVE-2026-5606?
To fix CVE-2026-5606, update the PHPGurukul Online Shopping Portal Project to the latest version or apply patches that address SQL injection vulnerabilities.
What systems are affected by CVE-2026-5606?
CVE-2026-5606 affects version 2.1 of PHPGurukul Online Shopping Portal Project.
What type of vulnerability is CVE-2026-5606?
CVE-2026-5606 is characterized as a SQL Injection vulnerability impacting the order-details.php file.
How can CVE-2026-5606 be exploited?
CVE-2026-5606 can be exploited by an attacker manipulating parameters sent to the order-details.php file, allowing unauthorized access to the database.