CVE-2026-1160: PHPGurukul Directory Management System Search index.php sql injection
A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of the component Search. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1160?
CVE-2026-1160 has a high severity due to the potential for SQL injection that can lead to unauthorized database access.
How do I fix CVE-2026-1160?
To fix CVE-2026-1160, validate and sanitize all user inputs in the searchdata parameter to prevent SQL injection.
What components are affected by CVE-2026-1160?
CVE-2026-1160 affects the Search component of the PHPGurukul Directory Management System version 1.0.
What kind of attack can exploit CVE-2026-1160?
CVE-2026-1160 can be exploited through SQL injection attacks, allowing attackers to manipulate backend databases.
Who is the vendor for CVE-2026-1160?
The vendor for CVE-2026-1160 is PHPGurukul, which developed the Directory Management System.