A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been rated as critical. This vulnerability affects unknown code of the file /admin/add-subadmins.php. This manipulation of the argument sadminusername causes sql injection.

This vulnerability appears as CVE-2026-5838. The attack may be initiated remotely. In addition, an exploit is available.