CVE-2026-5838
MEDIUMPHPGurukul News Portal Project add-subadmins.php sql injection
Title source: cnaDescription
A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the file /admin/add-subadmins.php. This manipulation of the argument sadminusername causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Scores
CVSS v3
4.7
EPSS
0.0004
EPSS Percentile
10.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-74
CWE-89
Status
published
Products (1)
PHPGurukul/News Portal Project
4.1
Published
Apr 09, 2026
Tracked Since
Apr 09, 2026