CVE-2026-1424

MEDIUM

PHPGurukul News Portal 1.0 - Unrestricted File Upload in Profile Pic Handler

Title source: llm
STIX 2.1

Description

A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.342840
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.342840
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.736637
Product product
https://phpgurukul.com/

Scores

CVSS v3 4.7
EPSS 0.0043
EPSS Percentile 34.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-434
Status published
Products (1)
phpgurukul/news_portal 1.0
Published Jan 26, 2026
Tracked Since Feb 18, 2026