Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nishant_Kumar

#19154of 53,625
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-44748
8.1
2025-11-03
Phpgurukul · Phpgurukul News Portal · CVE-2025-12615
**Name of the Vulnerable Software and Affected Versions** PHPGurukul News Portal version 1.0 **Description** A security issue exists in PHPGurukul News Portal. Manipulation of the `SECRET KEY` argument within an unknown function in the `/onps/settings.py` file results in the use of a hard-coded cryptographic key. This attack can be performed remotely and is considered difficult to exploit, but the exploit has been publicly disclosed. **Recommendations** Versions prior to 1.0 should be updated. As a temporary workaround, restrict access to the `/onps/settings.py` file to minimize the risk of exploitation.
PT-2025-44749
5.9
2025-11-03
Phpgurukul · Phpgurukul News Portal · CVE-2025-12616
**Name of the Vulnerable Software and Affected Versions** PHPGurukul News Portal version 1.0 **Description** A flaw exists in PHPGurukul News Portal 1.0 where manipulation of an unknown function within the `/onps/settings.py` file can lead to the insertion of sensitive information into debugging code. This attack can be initiated remotely and is considered to have high complexity and difficult exploitability. The exploit is publicly available. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.