A security flaw has been discovered in projectworlds Online Art Gallery Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /?pass=1. The manipulation of the argument fnm results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
References
| Link | Resource |
|---|---|
| https://github.com/hmKunlun/projectworldcve/issues/1 | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.349735 | Permissions Required VDB Entry |
| https://vuldb.com/?id.349735 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.768057 | Third Party Advisory VDB Entry |
Configurations
History
09 Mar 2026, 16:31
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| First Time |
Projectworlds
Projectworlds online Art Gallery Shop |
|
| References | () https://github.com/hmKunlun/projectworldcve/issues/1 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.349735 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.349735 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.768057 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:projectworlds:online_art_gallery_shop:1.0:*:*:*:*:*:*:* |
08 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-08 19:16
Updated : 2026-03-09 16:31
NVD link : CVE-2026-3757
Mitre link : CVE-2026-3757
CVE.ORG link : CVE-2026-3757
JSON object : View
Products Affected
projectworlds
- online_art_gallery_shop
