{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aphpgurukulblood_donor_management_system1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phpgurukul:blood_donor_management_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90840"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Blood Donor Management System (1.0)"],"_cs_severities":["high"],"_cs_tags":["web-application","authentication-bypass","vulnerability"],"_cs_type":"advisory","_cs_vendors":["PHPGurukul"],"content_html":"\u003cp\u003eA critical authentication vulnerability has been identified in the PHPGurukul Blood Donor Management System version 1.0. The flaw resides within the __construct function of the admin controller located at /application/controllers/admin/Dashboard.php. By manipulating this function, a remote, unauthenticated attacker can circumvent the application's authentication logic to access administrative functions. The vulnerability is publicly disclosed, and proof-of-concept exploit code is currently available, increasing the risk of opportunistic exploitation by malicious actors. Organizations utilizing this system should restrict external access to the administrative dashboard or transition to a secure alternative, as no vendor-provided patch has been documented.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized actors to bypass authentication to the administrative panel. This can result in full administrative control over the Blood Donor Management System, potentially leading to unauthorized data exfiltration, database manipulation, or the compromise of sensitive donor and patient information managed by the platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict network access to the admin dashboard interface to trusted management IP ranges via firewall rules.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to filter suspicious requests targeting /application/controllers/admin/Dashboard.php.\u003c/li\u003e\n\u003cli\u003eEvaluate the necessity of the Blood Donor Management System 1.0 installation; given the lack of patching, consider decommissioning or replacing the system.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous, unauthenticated requests targeting administrative URI paths.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T01:37:34Z","date_published":"2026-09-15T01:37:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-phpgurukul-auth-bypass/","summary":"PHPGurukul Blood Donor Management System 1.0 is vulnerable to an authentication bypass in the admin dashboard, allowing remote attackers to gain unauthorized administrative access.","title":"Authentication Bypass in PHPGurukul Blood Donor Management System","url":"https://feed.craftedsignal.io/briefs/2026-09-phpgurukul-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:phpgurukul:blood_donor_management_system:1.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}