CVE-2026-90846: PHPGurukul Daily Expense Tracker System forgot-password.php sql injection
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerable forgot-password endpoint can be attacked remotely without privileges or user interaction. Public exploit disclosure increases the likelihood of attempted exploitation.
Which inputs and endpoint should be investigated?
Investigate /dets/forgot-password.php, specifically handling of the email and contactno arguments. The affected function within that file is not identified in the available data.
What impact can successful exploitation have?
The supplied severity vector indicates low-impact compromise of confidentiality, integrity, and availability. The issue is classified as SQL injection.