Phpgurukul · Phpgurukul News Portal · CVE-2025-12615
**Name of the Vulnerable Software and Affected Versions**
PHPGurukul News Portal version 1.0
**Description**
A security issue exists in PHPGurukul News Portal. Manipulation of the `SECRET KEY` argument within an unknown function in the `/onps/settings.py` file results in the use of a hard-coded cryptographic key. This attack can be performed remotely and is considered difficult to exploit, but the exploit has been publicly disclosed.
**Recommendations**
Versions prior to 1.0 should be updated. As a temporary workaround, restrict access to the `/onps/settings.py` file to minimize the risk of exploitation.