# CVE-2025-12616

## Summary

- **CVE ID:** CVE-2025-12616
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-215, CWE-200
- **Published:** Nov 3, 2025
- **Last Modified:** Mar 13, 2026

## Description

A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used.

## Affected Products

- PHPGurukul — News Portal (1.0)

## References

- [CNA](https://vuldb.com/?id.330910)
- [CNA](https://vuldb.com/?ctiid.330910)
- [CNA](https://vuldb.com/?submit.678649)
- [CNA](https://github.com/NishantKumar-CSE/News-Portal-Python-Django-Project/blob/main/Information%20Disclosure%20via%20Debug%20Mode.md)
- [CNA](https://phpgurukul.com/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.54%
- **EPSS Percentile:** 43.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._