CVE-2026-90845

Summary

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.

Affected Software

VendorProductVersion RangeStatus
PHPGurukulDaily Expense Tracker System1.1affected

Weaknesses

  • CWE-79: Cross Site Scripting
  • CWE-94: Code Injection

References