A SQL injection vulnerability was found in PHPGurukul News Portal Project 4.1, affecting the /news-details.php file. The vulnerability is due to improper handling of user input in the Comment argument. This allows an attacker to inject malicious SQL code, potentially leading to unauthorized access or data manipulation. The attack can be launched remotely, and the exploit has been made public.
A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1, affecting an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes SQL injection. The attack may be initiated remotely. Users should review compensating controls and monitor for suspicious activity while remediation is planned.