CVE-2026-90517

Summary

A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used.

Affected Software

VendorProductVersion RangeStatus
PHPGurukulBank Locker Management System1.0affected

Weaknesses

  • CWE-639: Authorization Bypass
  • CWE-285: Improper Authorization

References