在 PHPGurukul 献血者管理系统 1.0 中发现了一个漏洞。受影响的组件是“Admin Controllers”,具体位于文件 中的 函数。通过操纵该函数可触发不当的身份认证(Improper Authentication)漏洞。该攻击可远程发起。利用代码(PoC)已公开,可能存在被实际利用的风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHPGurukul | Blood Donor Management System | 1.0 |
cpe:2.3:a:phpgurukul:blood_donor_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90841 | 7.3 HIGH | PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injection |
| CVE-2026-90842 | 3.7 LOW | PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file |
No comments yet