CVE-2026-90851: PHPGurukul Hostel Management System checklogin.php access control
Published Sep 15, 2026
·Updated
A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected Software
1 affected component
Phpgurukul Hostel Management System=3.0
Event History
Sep 15, 2026
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable and requires low privileges. No user interaction is required.
2
What is the likely impact if exploitation succeeds?
Successful exploitation may affect the confidentiality, integrity, and availability of the affected system at a low impact level. The issue involves improper access controls through manipulation of the ID argument.
3
Is there public exploit availability?
Yes. An exploit has been published, so organizations should treat exposed instances as more likely to be targeted.