← Vulnerability feed

Vulnerability record · CVE-2021-37808 · published 27 October 2021

CVE-2021-37808: Phpgurukul news portal sql injection vulnerability

Phpgurukul · News Portal

SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.

5.9 CVSS 3.1 Medium EPSS 1.8% · top 21.9% CWE-89 · SQL injection
5.9CVSS 3.1 base score, v2 4.3
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-37808 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-69991Phpgurukul news portal sql injection vulnerabilityphpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.EPSS 0.46%9.8CVE-2025-69992Phpgurukul news portal out-of-bounds read vulnerabilityphpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server witho…EPSS 0.59%9.1CVE-2025-69990Phpgurukul news portal vulnerabilityphpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be dele…EPSS 0.45%6.9CVE-2025-4880Phpgurukul news portal injection vulnerabilityA vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality o…EPSS 0.58%6.9CVE-2025-4873Phpgurukul news portal injection vulnerabilityA vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality o…EPSS 0.58%6.9CVE-2025-4874Phpgurukul news portal injection vulnerabilityA vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is some unknown functionality of t…EPSS 0.58%6.9CVE-2025-1859Phpgurukul news portal injection vulnerabilityA vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some unknown processing of the fi…EPSS 0.49%2.9CVE-2025-12616Phpgurukul news portal information exposure vulnerabilityA vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a m…EPSS 0.54%

Source: NIST National Vulnerability Database (record CVE-2021-37808), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.