CVE-2023-38890
HIGHOnline Shopping Portal Project 3.1 - SQL Injection
Title source: llmDescription
Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.
Exploits (3)
Scores
CVSS v3
8.8
EPSS
0.0321
EPSS Percentile
87.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
phpgurukul/online_shopping_portal
3.1
Published
Aug 18, 2023
Tracked Since
Feb 18, 2026