Description
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection enabling unauthorized data access and modification
Action: Immediate Patch
AI Analysis

Impact

A flaw exists in the forgot-password.php script of the PHPGurukul Daily Expense Tracker System that allows attackers to supply crafted values for the email or contactno parameters. Those are incorporated directly into a database query, providing a classic SQL injection vector. If exploited, an adversary can read from, modify, or delete records in the underlying database, resulting in loss of confidentiality of expense data and potential integrity violations.

Affected Systems

The vulnerability is present in PHPGurukul Daily Expense Tracker System version 1.1. Only the listed product and version are affected.

Risk and Exploitability

The CVSS score of 6.9 classifies the flaw as moderate severity, while the EPSS score of less than 1% suggests a very low exploitation probability in the current environment. The vulnerability is not listed in the CISA KEV catalog. Attack can be carried out remotely by merely sending a crafted request to the exposed script; the description does not specify whether authentication is required, so the exact scope of potential targets remains uncertain.

Generated by OpenCVE AI on September 17, 2026 at 19:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a version that addresses the SQL injection in forgot-password.php
  • Implement robust input validation and sanitization for the "email" and "contactno" fields before they are used in database queries
  • Replace vulnerable string concatenation with prepared statements or parameterized queries in the password recovery functionality

Generated by OpenCVE AI on September 17, 2026 at 19:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Title PHPGurukul Daily Expense Tracker System forgot-password.php sql injection
First Time appeared Phpgurukul
Phpgurukul daily Expense Tracker System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:phpgurukul:daily_expense_tracker_system:*:*:*:*:*:*:*:*
Vendors & Products Phpgurukul
Phpgurukul daily Expense Tracker System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Phpgurukul Daily Expense Tracker System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:40:04.472Z

Reserved: 2026-09-14T05:07:17.790Z

Link: CVE-2026-90846

cve-icon Vulnrichment

Updated: 2026-09-15T14:40:00.525Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T01:16:54.230

Modified: 2026-09-15T15:17:30.700

Link: CVE-2026-90846

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')