PT-2025-44748 · Phpgurukul · Phpgurukul News Portal

Nishant_Kumar

·

Published

2025-11-03

·

Updated

2025-11-10

·

CVE-2025-12615

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul News Portal version 1.0
Description A security issue exists in PHPGurukul News Portal. Manipulation of the SECRET KEY argument within an unknown function in the /onps/settings.py file results in the use of a hard-coded cryptographic key. This attack can be performed remotely and is considered difficult to exploit, but the exploit has been publicly disclosed.
Recommendations Versions prior to 1.0 should be updated. As a temporary workaround, restrict access to the /onps/settings.py file to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-12615

Affected Products

Phpgurukul News Portal