PHPGurukul Online Shopping Portal
cpe:2.3:a:phpgurukul:online_shopping_portal:*:*:*:*:*:*:*
- 2.0
A SQL injection vulnerability has been identified in PHPGurukul Online Shopping Portal version 2.0. The issue arises in the forgot-password.php file, where the email parameter can be manipulated to inject malicious SQL queries.
Exploitation of this vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation.
To reproduce this vulnerability, send a request to forgot-password.php with a crafted email parameter that includes SQL injection payloads. A time-based payload, such as one that uses the SQL 'SLEEP' function, can be employed to demonstrate the injection by causing a delay in the server's response.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.