CVE-2024-44659

Executive Summary

CVE‑2024‑44659 exposes PHPGurukul Online Shopping Portal 2.0 to unauthenticated SQL injection through the 'email' field in forgot‑password.php. An attacker can manipulate the query to retrieve, modify, or delete user data, reset passwords, or gain administrative access. The flaw allows bypassing authentication and potentially escalating privileges, posing a high risk to confidentiality, integrity, and availability of the application and its underlying database.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2025-11-17T20:15:49.310 - Last Modified: 2026-09-28T14:10:00.213

Original Description: PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

"Intuition will tell the thinking mind where to look next."

— Jonas Salk
Source: NVD