CVE-2024-44659
Executive Summary
CVE‑2024‑44659 exposes PHPGurukul Online Shopping Portal 2.0 to unauthenticated SQL injection through the 'email' field in forgot‑password.php. An attacker can manipulate the query to retrieve, modify, or delete user data, reset passwords, or gain administrative access. The flaw allows bypassing authentication and potentially escalating privileges, posing a high risk to confidentiality, integrity, and availability of the application and its underlying database.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2025-11-17T20:15:49.310 - Last Modified: 2026-09-28T14:10:00.213
Original Description: PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.
"Intuition will tell the thinking mind where to look next."
— Jonas Salk