Junglewise Threat Intelligence

CVE-2026-90845: PHPGurukul Daily Expense Tracker System stored cross-site scripting

CVE-2026-90845 · Severity: low · CVSS 3.5 · Published 2026-09-15

Technologies: Phpgurukul Daily Expense Tracker System. Vendors: Phpgurukul.

Executive brief

PHPGurukul Daily Expense Tracker System is a web-based accounting tool used to log and manage personal expenses. The application fails to sanitize user input before displaying it in the browser, allowing attackers to inject malicious scripts that execute in the accounts of other users. An attacker can steal session cookies, harvest credentials, or perform unauthorized actions on behalf of victims.

Technical details

This is a stored cross-site scripting (CWE-79) vulnerability in which user-supplied data (full name, expense items, costs, and profile fields) is rendered directly into HTML using raw PHP echo statements without output encoding. The vulnerable component is present across multiple pages including sidebar.php, manage-expense.php, and several report-detailed pages. Exploitation requires authentication but no additional user interaction beyond the attacker injecting a payload (via the expense form or profile update). An authenticated attacker can inject JavaScript that persists in the database and executes in the browsers of all other users who view the affected pages, particularly the sidebar which is loaded on every authenticated page. No patch information is currently available.

Affected products

  • PHPGurukul Daily Expense Tracker System 1.1

Timeline

  • 2026-08-12: disclosed: Vulnerability reported on GitHub
  • 2026-09-15: advisory

References

Related threats