


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the c…
Published:
1 March 2026 at 23:00:00
Alert date:
2 March 2026 at 04:01:00
Source:
nvd.nist.gov
Web Technologies
A SQL injection vulnerability was discovered in projectworlds Online Art Gallery Shop version 1.0. The vulnerability affects the Registration Handler component, specifically in the /admin/registration.php file through manipulation of the 'fname' parameter. The attack can be launched remotely and exploits have been made publicly available. This allows attackers to potentially access, modify, or extract sensitive data from the application's database through malicious SQL queries.
Technical details
Mitigation steps:
Affected products:
projectworlds Online Art Gallery Shop 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3406
https://github.com/ubfbuz3/cve/issues/55
https://vuldb.com/?ctiid.348301
https://vuldb.com/?id.348301
https://vuldb.com/?submit.763740
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
