{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/daily-expense-tracker-system-1.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phpgurukul:daily_expense_tracker_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90844"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Daily Expense Tracker System (1.1)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sql-injection","cve-2026-90844"],"_cs_type":"advisory","_cs_vendors":["PHPGurukul"],"content_html":"\u003cp\u003ePHPGurukul Daily Expense Tracker System version 1.1 contains a SQL injection vulnerability within the login component. The vulnerability is located in the '/dets/index.php' file, where the 'email' parameter fails to properly sanitize user-supplied input before passing it to database queries. An unauthenticated remote attacker can supply crafted SQL payloads via the email argument to manipulate back-end queries. This allows for unauthorized data access, potential authentication bypass, or administrative compromise of the underlying database. The vulnerability has been publicly disclosed and is considered exploitable by remote actors. Defenses should focus on monitoring HTTP requests to the identified login endpoint for signs of SQL injection patterns.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to interact directly with the application database, potentially resulting in the exfiltration of user credentials, financial records, or system configuration data. In high-privilege scenarios, this may facilitate a full compromise of the application server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize remediation by updating or patching the PHPGurukul Daily Expense Tracker System to a version that addresses CVE-2026-90844. As the component is vulnerable to SQL injection, ensure that all input handling in 'index.php' utilizes prepared statements or parameterized queries.\u003c/p\u003e\n","date_modified":"2026-09-15T01:38:00Z","date_published":"2026-09-15T01:37:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-phpgurukul-sql-injection/","summary":"An unauthenticated SQL injection vulnerability in the login component of PHPGurukul Daily Expense Tracker System 1.1 allows remote attackers to execute arbitrary database queries.","title":"SQL Injection in PHPGurukul Daily Expense Tracker System","url":"https://feed.craftedsignal.io/briefs/2026-09-phpgurukul-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Daily Expense Tracker System (1.1)","version":"https://jsonfeed.org/version/1.1"}