VYPR

small-crm-login-unserialize

by JdExploit

CVEs (1)

  • CVE-2026-90575LowSep 13, 2026
    risk 0.24cvss 3.7epss 0.00

    A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack…