An unauthenticated SQL injection vulnerability exists in PuneethReddyHC Online Shopping through the /action.php prId parameter. Using a post request does not sanitize the user input.
View the template here CVE-2021-41648.yaml
References:
https://github.com/MobiusBinary/CVE-2021-41648