CVE-2026-90842
Deferred Deferred - Pending Action

Password Hard-Coding in PHPGurukul Blood Donor Management System

Vulnerability report for CVE-2026-90842, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulDB

Description

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword causes cleartext storage in a file or on disk. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
phpgurukul blood_donor_management_system 1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-313 The product stores sensitive information in cleartext in a file, or on disk.
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the PHPGurukul Blood Donor Management System 1.0 storing passwords in cleartext or using weak MD5 hashing without salt. Admin passwords are stored and processed entirely in plaintext, while user passwords use unsalted MD5, making them vulnerable to brute-force attacks. The issue allows attackers with database access to extract and misuse credentials.

Detection Guidance

Check for plaintext password storage in the application/models/admin/Login_Model.php file or database. Look for admin passwords stored without hashing and user passwords hashed with unsalted MD5. Inspect login and password change processes for raw password comparisons.

Impact Analysis

If exploited, attackers could gain access to admin accounts directly due to plaintext storage or crack user passwords via MD5 hashing. This could lead to unauthorized access to sensitive data, system manipulation, or further attacks using compromised credentials.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for secure password storage and data protection. Plaintext storage and weak hashing fail to meet encryption and access control standards, risking non-compliance and potential legal penalties.

Mitigation Strategies

Migrate to secure password hashing using PHP's password_hash() and password_verify() with bcrypt (cost factor 12). Hash existing plaintext admin passwords and upgrade user passwords from MD5 to bcrypt. Apply consistent hashing across admin and user systems and conduct regular security audits.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90842. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart