Description
A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (XSS) via untrusted input
Action: Patch Now
AI Analysis

Impact

A flaw exists in PHPGurukul Daily Expense Tracker System 1.1 that allows the FullName parameter in sidebar.php to be processed without proper sanitization. This results in reflected cross‑site scripting attacks that can be triggered remotely. An attacker who successfully injects malicious JavaScript can execute code in the victim’s browser session, potentially collecting credentials, hijacking the session, or performing malicious actions on behalf of the user.

Affected Systems

PHPGurukul Daily Expense Tracker System version 1.1 is affected. No additional versions are listed, and the vulnerability is tied to the sidebar.php script that processes the FullName argument.

Risk and Exploitability

CVSS 5.1 indicates a medium severity vulnerability. The EPSS score is < 1%, and the issue is not listed in CISA KEV. The attack vector is remote, and a functional exploit has already been published, making this flaw a moderate risk for exposed installations.

Generated by OpenCVE AI on September 17, 2026 at 18:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install the latest official update of PHPGurukul Daily Expense Tracker System that addresses the XSS flaw.
  • Add server‑side validation and sanitization for the FullName parameter and apply output encoding such as htmlspecialchars before rendering.
  • Restrict access to the sidebar page to authenticated roles only and enforce least‑privilege access controls.

Generated by OpenCVE AI on September 17, 2026 at 18:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
Title PHPGurukul Daily Expense Tracker System sidebar.php cross site scripting
First Time appeared Phpgurukul
Phpgurukul daily Expense Tracker System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:phpgurukul:daily_expense_tracker_system:*:*:*:*:*:*:*:*
Vendors & Products Phpgurukul
Phpgurukul daily Expense Tracker System
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Phpgurukul Daily Expense Tracker System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:54:39.846Z

Reserved: 2026-09-14T05:07:14.490Z

Link: CVE-2026-90845

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:04.508Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T01:16:54.030

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-90845

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')