---
id: CVE-2026-90842
title: A weakness has been identified in PHPGurukul Blood Donor Management System 1.0
summary: >-
  A weakness has been identified in PHPGurukul Blood Donor Management System
  1.0. Affected by this issue is some unknown functionality of the file
  application/models/admin/Login_Model.php. This manipulation of the argument
  password/email/c…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-312
  - CWE-313
vendor: PHPGurukul
product: Blood Donor Management System
affected:
  - blood_donor_management_system 1.0
published: '2026-09-15'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T19:17:46.613'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90842'
references:
  - url: 'https://github.com/usernamevnq/CVEs/issues/3'
    label: cna@vuldb.com
  - url: 'https://phpgurukul.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90842'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/925629'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403394'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403394/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T19:10:16.753496Z'
epss: 0.00307
epssPercentile: 0.20847
ingestedAt: '2026-09-15T00:17:47.356Z'
---

## Overview

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword causes cleartext storage in a file or on disk. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
