CVE-2026-90575: PHPGurukul Small CRM Login Success login.php unserialize deserialization
A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an authenticated account or user interaction?
No. The vulnerability is remotely exploitable and requires no privileges or user interaction, although the attack complexity is rated high.
Which systems are in scope for this issue?
The affected product and version identified in the available data are PHPGurukul Small CRM 4.0. The vulnerable code path is the Login Success Handler in /crm/login.php.
Is exploit code available?
Yes. The exploit has been publicly disclosed and could be used in attacks, despite exploitation being described as difficult.