在 PHPGurukul Daily Expense Tracker System 1.1 中检测到一个漏洞。该漏洞影响位于文件 /dets/index.php 的未知代码,属于登录组件。通过操纵参数 email 可触发 SQL 注入攻击。该漏洞可被远程利用,且相关漏洞利用详情已公开,可能被实际使用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHPGurukul | Daily Expense Tracker System | 1.1 |
cpe:2.3:a:phpgurukul:daily_expense_tracker_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90846 | 7.3 HIGH | PHPGurukul Daily Expense Tracker System forgot-password.php sql injection |
| CVE-2026-90851 | 6.3 MEDIUM | PHPGurukul Hostel Management System checklogin.php access control |
| CVE-2026-90845 | 3.5 LOW | PHPGurukul Daily Expense Tracker System sidebar.php cross site scripting |
| CVE-2026-90850 | 2.4 LOW | PHPGurukul Hostel Management System manage-students.php cross site scripting |
No comments yet