CVE-2025-69992
BaseFortify
Publication date: 2026-01-13
Last updated on: 2026-01-16
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| phpgurukul | news_portal | 4.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in phpgurukul News Portal Project V4.1 is a file upload vulnerability in the upload.php script. It allows an attacker to upload files of any format to the server without any identity authentication, meaning unauthorized users can upload potentially malicious files. [1]
How can this vulnerability impact me? :
This vulnerability can allow attackers to upload malicious files to the server, which could lead to unauthorized code execution, data compromise, server takeover, or defacement of the website. It poses a significant security risk to the affected system. [1]