A vulnerability identified as critical has been detected in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /admin/check_availability.php. Performing a manipulation of the argument Username results in sql injection.
This vulnerability is known as CVE-2026-5840. Remote exploitation of the attack is possible. Furthermore, an exploit is available.