Impact
A vulnerability exists in the forgot-password.php component of PHPGurukul Daily Expense Tracker System. By manipulating the "email" or "contactno" input, an attacker can inject arbitrary SQL code. The flaw falls under CWE-74 (Incorrect Parsing of Input) and CWE-89 (SQL Injection). If exploited, the attacker could read, modify, or delete database records, leading to confidentiality and integrity compromise of expense data.
Affected Systems
The issue affects PHPGurukul Daily Expense Tracker System, current release version 1.1. No other versions have been identified in the CNA data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available. The vulnerability is listed as not part of the CISA KEV catalog. The attack vector is remote, requiring only the ability to send crafted requests to the vulnerable script. It appears that no authentication is required, but this is inferred from the description, so any internet‑exposed instance could be a potential target.
OpenCVE Enrichment