Description
A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Problem types
Product status
Timeline
| 2025-12-31: | Advisory disclosed |
| 2025-12-31: | VulDB entry created |
| 2026-01-14: | VulDB entry last update |
Credits
hackerfactory (VulDB User)
References
github.com/...-CRM-in-PHP/blob/main/Broken Access Control.md
vuldb.com/?id.339151 (VDB-339151 | PHPGurukul Small CRM edit-user.php authorization)
vuldb.com/?ctiid.339151 (VDB-339151 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.727430 (Submit #727430 | PHPGurukul PHPGurukul Small Customer Relationship Management v4.0 Missing Authorization)
github.com/...-CRM-in-PHP/blob/main/Broken Access Control.md
phpgurukul.com/