PHPGurukul Online Shopping Portal SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in PHPGurukul Online Shopping Portal version 2.0. The issue arises in the admin page, where the username parameter can be manipulated to inject malicious SQL queries.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can interfere with the application's database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.

Reproduction

To reproduce this vulnerability, navigate to the admin login page of the PHPGurukul Online Shopping Portal. Inject a SQL payload into the username parameter. A time-based SQL injection payload, such as one that uses the SQL 'SLEEP' function, can be employed to demonstrate the vulnerability by causing a delay in the server's response.

Added: Nov 17, 2025, 7:19 PM
Updated: Nov 17, 2025, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
3.1
exploitability
6.8
remediation
0.0
relevance
1.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.