A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/NishantKumar-CSE/News-Portal-Python-Django-Project/blob/main/Information%20Disclosure%20via%20Debug%20Mode.md | Exploit Third Party Advisory |
| https://phpgurukul.com/ | Product |
| https://vuldb.com/?ctiid.330910 | Permissions Required VDB Entry |
| https://vuldb.com/?id.330910 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.678649 | Third Party Advisory VDB Entry |
| https://github.com/NishantKumar-CSE/News-Portal-Python-Django-Project/blob/main/Information%20Disclosure%20via%20Debug%20Mode.md | Exploit Third Party Advisory |
Configurations
History
05 Nov 2025, 13:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/NishantKumar-CSE/News-Portal-Python-Django-Project/blob/main/Information%20Disclosure%20via%20Debug%20Mode.md - Exploit, Third Party Advisory | |
| References | () https://phpgurukul.com/ - Product | |
| References | () https://vuldb.com/?ctiid.330910 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.330910 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.678649 - Third Party Advisory, VDB Entry | |
| First Time |
Phpgurukul
Phpgurukul news Portal |
|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:phpgurukul:news_portal:1.0:*:*:*:*:*:*:* |
03 Nov 2025, 21:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/NishantKumar-CSE/News-Portal-Python-Django-Project/blob/main/Information%20Disclosure%20via%20Debug%20Mode.md - |
03 Nov 2025, 04:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-03 04:15
Updated : 2025-11-05 13:38
NVD link : CVE-2025-12616
Mitre link : CVE-2025-12616
CVE.ORG link : CVE-2025-12616
JSON object : View
Products Affected
phpgurukul
- news_portal
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-215Insertion of Sensitive Information Into Debugging Code
NVD-CWE-noinfo