CVE-2026-1424

MEDIUM

Phpgurukul News Portal - Improper Access Control

Title source: rule
STIX 2.1

Description

A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Exploits (1)

Scores

CVSS v3 4.7
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-434
Status published
Products (1)
phpgurukul/news_portal 1.0
Published Jan 26, 2026
Tracked Since Feb 18, 2026