CVE-2026-90846 | CVSS: 7.3 | 严重级别: HIGH
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
参考链接:
• https://github.com/usernamevnq/CVEs/issues/8
• https://phpgurukul.com/
• https://vuldb.com/cve/CVE-2026-90846
📌 数据来源: NVD 官方
⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。