Description
A security vulnerability has been detected in projectworlds Online Art Gallery Shop 1.0. This affects an unknown part of the file /admin/adminHome.php. Such manipulation of the argument reach_nm leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Problem types
Product status
Timeline
| 2026-03-07: | Advisory disclosed |
| 2026-03-07: | VulDB entry created |
| 2026-03-07: | VulDB entry last update |
Credits
kunlun (VulDB User)
References
vuldb.com/?id.349737 (VDB-349737 | projectworlds Online Art Gallery Shop adminHome.php sql injection)
vuldb.com/?ctiid.349737 (VDB-349737 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.768059 (Submit #768059 | projectworlds Online Art Gallery Shop Project V1.0 SQL Injection)
github.com/hmKunlun/projectworldcve/issues/3