MEDIUM 5.5 NVD
CVE-2026-90841
A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /app
A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument fromdate/todate results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
References
- https://github.com/usernamevnq/CVEs/issues/2
- https://phpgurukul.com/
- https://vuldb.com/cve/CVE-2026-90841
- https://vuldb.com/submit/925627
- https://vuldb.com/vuln/403393
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-09-15 via NVD.
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.