在 PHPGurukul 每日支出追踪系统 1.1 中发现一个缺陷。该问题影响 /dets/includes/sidebar.php 文件中某些未知处理逻辑。通过对参数 FullName 进行操纵可触发跨站脚本攻击(XSS)。该攻击可通过远程执行,且相关利用代码已公开,可能被攻击者用于实施攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHPGurukul | Daily Expense Tracker System | 1.1 |
cpe:2.3:a:phpgurukul:daily_expense_tracker_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90846 | 7.3 HIGH | PHPGurukul Daily Expense Tracker System forgot-password.php sql injection |
| CVE-2026-90844 | 7.3 HIGH | PHPGurukul Daily Expense Tracker System Login index.php sql injection |
| CVE-2026-90851 | 6.3 MEDIUM | PHPGurukul Hostel Management System checklogin.php access control |
| CVE-2026-90850 | 2.4 LOW | PHPGurukul Hostel Management System manage-students.php cross site scripting |
No comments yet