Description
A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit is publicly available and might be used.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-01-18: | Advisory disclosed |
| 2026-01-18: | VulDB entry created |
| 2026-01-28: | VulDB entry last update |
Credits
moasim (VulDB User)
References
vuldb.com/?id.341733 (VDB-341733 | PHPGurukul News Portal Add Sub-Admin add-subadmins.php improper authorization)
vuldb.com/?ctiid.341733 (VDB-341733 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.735483 (Submit #735483 | PHPGurukul News Portal Project in PHP and MySql 1.0 Improper Access Controls)
vuldb.com/?submit.736668 (Submit #736668 | PHPGurukul News Portal v1.0 Authorization Bypass (Duplicate))
github.com/...-Portal-Project-in-PHP-and-MySQL-in-PHPGurukul
phpgurukul.com/