THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-90575 (LOW 3.7) — A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remote

[NVD] CVE-2026-90575 (LOW 3.7) — A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remote

mednvdPublished 2026-09-13

CVE-2026-90575 CVSS: 3.7 LOW Published: 2026-09-13T18:16:50.117

A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exp

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90575