CVE-2025-12616
PHPGurukul News Portal settings.py insertion of sensitive information into debugging code
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used.
| CWE | CWE-215 CWE-200 |
| Vendor | phpgurukul |
| Product | news portal |
| Published | Nov 3, 2025 |
| Last Updated | Feb 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for phpgurukul news portal
Be the first to know when new low vulnerabilities affecting phpgurukul news portal are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
PHPGurukul / News Portal
1.0
References
vuldb.com: https://vuldb.com/?id.330910 vuldb.com: https://vuldb.com/?ctiid.330910 vuldb.com: https://vuldb.com/?submit.678649 github.com: https://github.com/NishantKumar-CSE/News-Portal-Python-Django-Project/blob/main/Information%20Disclosure%20via%20Debug%20Mode.md phpgurukul.com: https://phpgurukul.com/
Credits
๐ Nishant_Kumar (VulDB User)