CVE-2026-90519: PHPGurukul Bank Locker Management System add-locker-form.php unrestricted upload
A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The CVSS vector indicates that an attacker needs low privileges and can exploit the issue remotely over the network. No user interaction is required.
Is public exploit code available?
Yes. The available information states that an exploit has been made public and could be used in attacks.
Which deployments are identified as affected?
PHPGurukul Bank Locker Management System version 1.0 is identified as affected. The available information does not specify other affected or unaffected versions.