CVE-2025-12615

A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used.
Configurations

No configuration.

History

03 Nov 2025, 21:18

Type Values Removed Values Added
References () https://github.com/NishantKumar-CSE/News-Portal-Python-Django-Project/blob/main/Hard-coded%20Cryptographic%20Key.md - () https://github.com/NishantKumar-CSE/News-Portal-Python-Django-Project/blob/main/Hard-coded%20Cryptographic%20Key.md -

03 Nov 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-03 04:15

Updated : 2025-11-04 15:41


NVD link : CVE-2025-12615

Mitre link : CVE-2025-12615

CVE.ORG link : CVE-2025-12615


JSON object : View

Products Affected

No product.

CWE
CWE-320

Key Management Errors

CWE-321

Use of Hard-coded Cryptographic Key