CRITICAL🇵🇱 Wersja polska

CVE-2025-69990

CVSS 9.1v3.1pub. 2026-01-13upd. 2026-01-16

phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.

🤖 AI Analysis
How it works

The vulnerability (CWE-552) consists of insufficient validation and access control of the 'file' parameter in the remove_file.php script. An attacker can pass any file path on the server in this parameter, resulting in its deletion without permission verification. The attack vector is network-based, requires no authentication or user interaction, making exploitation trivial.

Impact

An attacker can permanently delete any files accessible to the web server process, including configuration files, application data, system files, or the entire application content, leading to data loss and service unavailability.

Mitigation & patch

Apply patches available from the vendor according to the references. Until an update is applied, it is recommended to remove or secure access to the remove_file.php file (e.g., through web server-level restrictions) and implement access controls and server-side file path validation.

Who is affected

Phpgurukul News Portal Project V4.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Phpgurukul News Portal

    APP
    Phpgurukul
    4.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-69992CRITICAL9.8PL ✓same product

Nieautoryzowany upload pliku dowolnego formatu w Phpgurukul News Portal

CVE-2025-69991CRITICAL9.8PL ✓same product

SQL Injection w Phpgurukul News Portal V4.1 (check_availablity.php)

CVE-2025-4874MEDIUM6.9same product

A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this i...

CVE-2025-4873MEDIUM6.9same product

A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vuln...

CVE-2025-4880MEDIUM6.9same product

A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vuln...