Description
A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword causes cleartext storage in a file or on disk. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks.
Published: 2026-09-14
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Immediate Patch
AI Analysis

Impact

A flaw in the login logic of the PHPGurukul Blood Donor Management System writes passwords and related credentials directly to a file on disk in clear text. This allows an attacker who can submit a modified login request to retrieve and later read the exposed credentials, compromising the confidentiality of user accounts. The weakness is a cleartext storage of sensitive information, classified as CWE-312 and CWE-313. An attacker can trigger this remotely, although the exploitation requires advanced privileges to alter login parameters and a high level of technical skill, and publicly available exploit code has been released.

Affected Systems

The affected product is PHPGurukul Blood Donor Management System version 1.0. The vulnerability resides in the file application/models/admin/Login_Model.php and is specific to this vendor’s implementation.

Risk and Exploitability

The CVSS score of 6.3 indicates a medium severity for this flaw. The EPSS score of < 1% suggests that the likelihood of exploitation is low, though the vulnerability remains remotely exploitable. The flaw is not listed in the CISA KEV catalog. Because the vulnerability can be triggered remotely and public exploit code exists, the risk of data leakage remains significant and should be mitigated promptly.

Generated by OpenCVE AI on September 17, 2026 at 18:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch or upgrade to a version that removes the cleartext file write operation.
  • If no patch is available, refactor Login_Model.php to hash passwords with a strong algorithm such as bcrypt before any storage operation and eliminate the file write that preserves plaintext credentials.
  • Ensure the directory where credential files are written has restrictive permissions so that only the application process can write, and configure monitoring or audit logging to detect unauthorized changes.

Generated by OpenCVE AI on September 17, 2026 at 18:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword causes cleartext storage in a file or on disk. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks.
Title PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file
First Time appeared Phpgurukul
Phpgurukul blood Donor Management System
Weaknesses CWE-312
CWE-313
CPEs cpe:2.3:a:phpgurukul:blood_donor_management_system:*:*:*:*:*:*:*:*
Vendors & Products Phpgurukul
Phpgurukul blood Donor Management System
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Phpgurukul Blood Donor Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T19:10:35.425Z

Reserved: 2026-09-14T05:03:41.232Z

Link: CVE-2026-90842

cve-icon Vulnrichment

Updated: 2026-09-15T19:10:26.553Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T00:17:31.337

Modified: 2026-09-15T19:17:46.613

Link: CVE-2026-90842

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information

  • CWE-313

    Cleartext Storage in a File or on Disk