phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.
https://github.com/hptcybersecurity/CVE/blob/main/CVE-2025-57148.md
https://doc.clickup.com/3897127/p/h/3pxt7-12496/7fdf159633a77d1