在 PHPGurukul Daily Expense Tracker System 1.1 中发现了一个漏洞。受影响的是文件 /dets/forgot-password.php 中的一个未知函数。该文件中的参数 email/contactno 的处理存在缺陷,可能导致 SQL 注入漏洞。该攻击可远程执行,且该漏洞的利用方式已公开,可能被攻击者利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHPGurukul | Daily Expense Tracker System | 1.1 |
cpe:2.3:a:phpgurukul:daily_expense_tracker_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90844 | 7.3 HIGH | PHPGurukul Daily Expense Tracker System Login index.php sql injection |
| CVE-2026-90851 | 6.3 MEDIUM | PHPGurukul Hostel Management System checklogin.php access control |
| CVE-2026-90845 | 3.5 LOW | PHPGurukul Daily Expense Tracker System sidebar.php cross site scripting |
| CVE-2026-90850 | 2.4 LOW | PHPGurukul Hostel Management System manage-students.php cross site scripting |
No comments yet