Description
A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unknown function of the file /admin/adminHome.ph. The manipulation of the argument social_twitter results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Problem types
Product status
Timeline
| 2026-06-04: | Advisory disclosed |
| 2026-06-04: | VulDB entry created |
| 2026-06-04: | VulDB entry last update |
Credits
shqnq (VulDB User)
References
vuldb.com/vuln/368365 (VDB-368365 | projectworlds Online Art Gallery Shop Project adminHome.ph sql injection)
vuldb.com/vuln/368365/cti (VDB-368365 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10875 (CVE-2026-10875 | CVE Analysis and Report)
vuldb.com/submit/831869 (Submit #831869 | projectworlds.com Online Art Gallery Shop Project 1.0 SQL Injection)
github.com/shq3526/cve/issues/10