CVE-2025-69992

phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:news_portal:4.1:*:*:*:*:*:*:*

History

16 Jan 2026, 18:23

Type Values Removed Values Added
First Time Phpgurukul news Portal
Phpgurukul
CPE cpe:2.3:a:phpgurukul:news_portal:4.1:*:*:*:*:*:*:*
References () https://github.com/Y4y17/CVE/blob/main/News%20Portal%20Project/File%20upload%20vulnerability.md - () https://github.com/Y4y17/CVE/blob/main/News%20Portal%20Project/File%20upload%20vulnerability.md - Exploit, Third Party Advisory

14 Jan 2026, 15:15

Type Values Removed Values Added
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

13 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 16:16

Updated : 2026-01-16 18:23


NVD link : CVE-2025-69992

Mitre link : CVE-2025-69992

CVE.ORG link : CVE-2025-69992


JSON object : View

Products Affected

phpgurukul

  • news_portal
CWE
CWE-125

Out-of-bounds Read