在 PHPGurukul 献血者管理系统 1.0 中发现了一个安全漏洞。该漏洞影响的是 /application/controllers/admin/Report.php 文件中 Report 端点的未知功能。通过操纵 fromdate/todate 参数可触发 SQL 注入。该攻击可远程发起。相关利用代码(exploit)已公开,可能被用于实际攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHPGurukul | Blood Donor Management System | 1.0 |
cpe:2.3:a:phpgurukul:blood_donor_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90840 | 7.3 HIGH | PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __construct impro |
| CVE-2026-90842 | 3.7 LOW | PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file |
No comments yet