CVE-2026-90518: PHPGurukul Bank Locker Management System sidebar.php access control
A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for review?
Deployments of PHPGurukul Bank Locker Management System 1.0 should be prioritized, particularly where the application is remotely reachable. The affected behavior is associated with sidebar.php and handling of the UserType argument.
What does an attacker need to exploit this issue?
The attacker can launch the attack remotely and requires low-level privileges. No user interaction is required, and a public exploit has been released.
What is the potential impact of successful exploitation?
Successful exploitation can result in low impact to confidentiality, integrity, and availability through improper access control. The available data does not identify which specific unauthorized functions or records become accessible.