A vulnerability was found in code-projects Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of the argument cat_id leads to sql injection.

This vulnerability is referenced as CVE-2026-19921. It is possible to launch the attack remotely. Furthermore, an exploit is available.