CVE-2026-90844: PHPGurukul Daily Expense Tracker System Login index.php sql injection
Published Sep 15, 2026
·Updated
A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
1 affected component
Phpgurukul Daily Expense Tracker System=1.1
Event History
Sep 15, 2026
CVE Published
via MITRE·12:15 AM
Data Sourced
via MITRE·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker can exploit it without authentication or user interaction by manipulating the email argument in the login component's /dets/index.php endpoint.
2
Is public exploit code available?
Yes. The available data states that the exploit is public and may be used.
3
How can I identify potentially affected installations?
Review deployments of PHPGurukul Daily Expense Tracker System version 1.1 and inspect the Login component at /dets/index.php, particularly handling of the email argument.