CVE-2026-0547 is an unrestricted file upload vulnerability affecting PHPGurukul Online Course Registration up to version 3.1. Specifically, it allows an authenticated attacker to upload arbitrary files by manipulating the 'photo' argument on the /admin/edit-student-profile.php page. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While public exploit code exists, there is no evidence of active exploitation, and it has not been added to CISA's KEV catalog. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1CPE matchmatch criteria | cpe:2.3:a:phpgurukul:online_course_registration:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.