PT-2026-3447 · Unknown · Phpgurukul Directory Management System

Nick_1321

·

Publicado

2026-01-19

·

Atualizado

2026-01-19

·

CVE-2026-1160

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Directory Management System version 1.0
Description A security issue exists in PHPGurukul Directory Management System 1.0 related to the Search component. The issue involves SQL injection, potentially allowing remote attackers to compromise the system. The vulnerability is located in the /index.php file and involves manipulation of the searchdata argument within an unknown function. The exploit for this issue has been publicly disclosed.
Recommendations Apply updates to address the vulnerability in the Search component. As a temporary workaround, restrict access to the /index.php file or the Search functionality until a patch is available.

Exploit

Correção

SQL injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1160

Produtos afetados

Phpgurukul Directory Management System