Description
A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used.
Problem types
Use of Hard-coded Cryptographic Key
Product status
Timeline
| 2025-11-02: | Advisory disclosed |
| 2025-11-02: | VulDB entry created |
| 2025-11-11: | VulDB entry last update |
Credits
Nishant_Kumar (VulDB User)
References
github.com/...ject/blob/main/Hard-coded Cryptographic Key.md
vuldb.com/?id.330909 (VDB-330909 | PHPGurukul News Portal settings.py hard-coded key)
vuldb.com/?ctiid.330909 (VDB-330909 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.678625 (Submit #678625 | PHPGurukul News Portal using Python Django and MySQL 1.0 Use of Hard-coded Cryptographic Key)
github.com/...ject/blob/main/Hard-coded Cryptographic Key.md
phpgurukul.com/