PT-2026-3447 · Unknown · Phpgurukul Directory Management System

Nick_1321

·

Published

2026-01-19

·

Updated

2026-01-19

·

CVE-2026-1160

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Directory Management System version 1.0
Description A security issue exists in PHPGurukul Directory Management System 1.0 related to the Search component. The issue involves SQL injection, potentially allowing remote attackers to compromise the system. The vulnerability is located in the /index.php file and involves manipulation of the searchdata argument within an unknown function. The exploit for this issue has been publicly disclosed.
Recommendations Apply updates to address the vulnerability in the Search component. As a temporary workaround, restrict access to the /index.php file or the Search functionality until a patch is available.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1160

Affected Products

Phpgurukul Directory Management System