CVE-2026-5838

MEDIUM

PHPGurukul News Portal Project add-subadmins.php sql injection

Title source: cna

Description

A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the file /admin/add-subadmins.php. This manipulation of the argument sadminusername causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 4.7
EPSS 0.0004
EPSS Percentile 10.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
PHPGurukul/News Portal Project 4.1
Published Apr 09, 2026
Tracked Since Apr 09, 2026