CVE-2026-90841

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.3
HIGH
CVSS v2 Base Score
7.5
HIGH

Description

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument fromdate/todate results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

Published
September 15, 2026 12:17 AM
Last Modified
September 15, 2026 12:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-74 CWE-89

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.