Junglewise Threat Intelligence

CVE-2026-90844: PHPGurukul Daily Expense Tracker System SQL injection in login

CVE-2026-90844 · Severity: high · CVSS 7.3 · Published 2026-09-15

Technologies: Phpgurukul Daily Expense Tracker System. Vendors: Phpgurukul.

Executive brief

PHPGurukul Daily Expense Tracker System is a web application for tracking personal expenses and managing financial records. A SQL injection vulnerability in the login page allows attackers to bypass authentication entirely without valid credentials, gaining full access to any user's account, personal expense data, and financial information. The flaw affects version 1.1 and is publicly exploitable.

Technical details

The vulnerability is a classic unauthenticated SQL injection (CWE-89) in the login component (/dets/index.php). The email parameter from the POST request is concatenated directly into a SQL query without sanitization or parameterized statements, while the password is hashed with MD5 before insertion. An attacker can inject SQL operators in the email field—such as `' OR '1'='1' LIMIT 1-- -`—to bypass authentication and login as the first user in the database or any known user. No server-side validation, escaping, or prepared statements are implemented. Network access is required and no authentication is needed to exploit this vulnerability. Remediation requires use of prepared statements with parameter binding and server-side input validation.

Affected products

  • PHPGurukul Daily Expense Tracker System 1.1

Timeline

  • 2026-08-12: disclosed: Vulnerability reported on GitHub
  • 2026-09-15: advisory: Published as CVE-2026-90844 in NVD

References

Related threats