Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q2gf-mw7m-x2mr

Опубликовано: 03 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 1.3
CVSS3: 5

Описание

A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used.

A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used.

EPSS

Процентиль: 16%
0.00052
Низкий

1.3 Low

CVSS4

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
nvd
3 месяца назад

A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used.

EPSS

Процентиль: 16%
0.00052
Низкий

1.3 Low

CVSS4

5 Medium

CVSS3