CVE-2026-90845: PHPGurukul Daily Expense Tracker System sidebar.php cross site scripting
Published Sep 15, 2026
·Updated
A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
1 affected component
Phpgurukul Daily Expense Tracker System=1.1
Event History
Sep 15, 2026
CVE Published
via MITRE·12:30 AM
Data Sourced
via MITRE·12:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and interaction are required to exploit this issue?
The CVSS vector indicates an attacker needs low-level privileges and user interaction. The attack can be performed remotely by manipulating the FullName argument.
2
Which deployments are known to be affected?
The issue is reported in PHPGurukul Daily Expense Tracker System version 1.1, in unknown processing associated with /dets/includes/sidebar.php.
3
Is public exploit material available?
Yes. The exploit has been published and may be used.