CVE-2026-90842
A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword causes cleartext storage in a file or on disk. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.20%
- CWE
- CWE-313, CWE-312
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- PHPGurukul Blood Donor Management System
Weakness type
Related vulnerabilities
- CVE-2025-5098 — KL-001-2025-003: Mobile Dynamix PrinterShare Mobile Print Gmail Oauth Token Disclosure
- CVE-2025-64305 — Columbia Weather Systems MicroServer Cleartext Storage in a File or on Disk
- CVE-2024-38280 — Cleartext Storage in a File or on Disk in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)
- CVE-2026-52783 — OpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others "storage.<id>.httpx_access_token" leads to Sensitive Data Exposure
- CVE-2026-24349 — A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Run
- CVE-2024-6785 — MXview One and MXview One Central Manager Series store cleartext credentials in a local file
- CVE-2024-30406 — Junos OS Evolved: ACX Series with Paragon Active Assurance Test Agent: A local high privileged attacker can recover other administrators credentials
- CVE-2024-20448 — Cisco Nexus Dashboard Fabric Controller Credential Information Disclosure Vulnerability