Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2669 articles · 104630 vulns · 38/41 feeds (7d)
← Back to list
6.3
CVE-2026-5640
phpgurukul · online shopping portal project

PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection

Description

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

Affected Products

VendorProductVersions
phpgurukulonline shopping portal project2.1

References

  • https://vuldb.com/vuln/355428(vdb-entry, technical-description)
  • https://vuldb.com/vuln/355428/cti(signature, permissions-required)
  • https://vuldb.com/submit/785985(third-party-advisory)
  • https://github.com/f1rstb100d/CVE/issues/18(exploit, issue-tracking)
  • https://phpgurukul.com/(product)

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-5640 | PHPGurukul Online Shopping Portal Project 2.1 Parameter /admin/update-image2.php filename sql injection
→ No new info (linked only)
CVSS 3.16.3 NONE
CISA KEV❌ No
Actively exploited❌ No
CWECWE-89, CWE-74
PublishedApr 6, 2026
Last enriched1d ago
Trending Score25
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-5641
PHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injection
Trending: 25
NONECVE-2026-5636
PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection
Trending: 25
NONECVE-2026-5639
PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection
Trending: 25
NONECVE-2026-5635
PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection
Trending: 25
NONECVE-2026-5583
PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection
Trending: 24

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 6, 2026
Discovered by ZDM
Apr 6, 2026