CVE-2026-90841 | CVSS: 7.3 | 严重级别: HIGH
A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument fromdate/todate results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
参考链接:
• https://github.com/usernamevnq/CVEs/issues/2
• https://phpgurukul.com/
• https://vuldb.com/cve/CVE-2026-90841
📌 数据来源: NVD 官方
⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。