A critical SQL injection vulnerability exists in PHPGurukul Online Shopping Portal Project 2.1. The vulnerability is located in the /order-details.php file of the Parameter Handler component, triggered by manipulation of the 'orderid' argument. The attack can be launched remotely.
| Vendor | Product | Versions |
|---|---|---|
| phpgurukul | online shopping portal project | 2.1 |