CVE-2026-90840: PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __construct improper authentication
A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be initiated remotely and requires no privileges or user interaction according to the supplied severity vector. A publicly available exploit may be used.
Which deployment is known to be affected?
The affected product is PHPGurukul Blood Donor Management System version 1.0. The issue is in the __construct function of /application/controllers/admin/Dashboard.php.
What is the likely impact of successful exploitation?
The severity vector indicates low impacts to confidentiality, integrity, and availability. The vulnerability is classified as improper authentication in the admin controller component.