SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-90575

LOW · CVSS 3.7 EPSS 0.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the unserialize function within the Login Success Handler of PHPGurukul Small CRM 4.0, allowing for remote deserialization attacks through manipulation of the geopluginURL argument. Although the attack complexity is high and exploitability is considered difficult, the public availability of the exploit necessitates that users of this CRM prioritize patching or mitigating this weakness to protect against potential exploitation. Organizations utilizing PHPGurukul Small CRM should assess their exposure and implement necessary security measures promptly.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90575
Severity
LOW
CVSS
3.7
EPSS
0.46%

Original NVD Description

A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks.