Junglewise Threat Intelligence

CVE-2026-90841: PHPGurukul Blood Donor Management System SQL injection in Report endpoint

CVE-2026-90841 · Severity: high · CVSS 7.3 · Published 2026-09-15

Technologies: Phpgurukul Blood Donor Management System. Vendors: Phpgurukul.

Executive brief

PHPGurukul Blood Donor Management System is a web application for managing blood donor records and generating reports. An unauthenticated attacker can exploit a SQL injection vulnerability in the Report endpoint to extract sensitive data (user and admin passwords), modify or delete database records, and potentially achieve remote code execution. The vulnerability is exposed because the authentication check is disabled and user input is directly concatenated into SQL queries without any validation or escaping.

Technical details

This is an unauthenticated SQL injection vulnerability (CWE-89) in the /admin/Report endpoint of PHPGurukul Blood Donor Management System v1.0. The vulnerable component is /application/controllers/admin/Report.php and /application/models/admin/Report_Model.php. The authentication check in the Report controller constructor is commented out, allowing public access without credentials. The vulnerability arises because the fromdate and todate POST parameters are concatenated directly into a raw SQL WHERE clause using $this->db->where("date(create_date) between '$fdate' and '$tdate'"), which CodeIgniter's Query Builder does not escape. An attacker can submit SQL injection payloads in either date field to execute arbitrary SQL queries, extract all database contents including plaintext admin passwords, modify records, or potentially execute file operations. The attack requires network access and no authentication.

Affected products

  • PHPGurukul Blood Donor Management System 1.0

Timeline

  • 2026-08-12: disclosed
  • 2026-09-15: advisory

References

Related threats