CVE-2026-5636 PUBLISHED

PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection

Assigner: VulDB
Reserved: 05.04.2026 Published: 06.04.2026 Updated: 06.04.2026

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor PHPGurukul
Product Online Shopping Portal Project
Versions
  • Version 2.1 is affected

References

Problem Types

  • SQL Injection CWE
  • Injection CWE