CVE-2026-5639: PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection
A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5639?
CVE-2026-5639 is classified as a critical vulnerability due to the potential for SQL injection.
How do I fix CVE-2026-5639?
To fix CVE-2026-5639, sanitize and validate all inputs in the /admin/update-image3.php file to mitigate SQL injection risks.
What component is affected by CVE-2026-5639?
CVE-2026-5639 affects the Parameter Handler component of the PHPGurukul Online Shopping Portal Project.
Which version of PHPGurukul Online Shopping Portal Project is impacted by CVE-2026-5639?
CVE-2026-5639 specifically impacts version 2.1 of the PHPGurukul Online Shopping Portal Project.
What type of attack does CVE-2026-5639 allow?
CVE-2026-5639 allows attackers to perform SQL injection, potentially compromising the database.