Junglewise Threat Intelligence

CVE-2026-90517: PHPGurukul Bank Locker Management System authentication bypass

CVE-2026-90517 · Severity: medium · CVSS 5.3 · Published 2026-09-13

Technologies: Phpgurukul Bank Locker Management System. Vendors: Phpgurukul.

Executive brief

The PHPGurukul Bank Locker Management System is a PHP-based web application used to manage customer locker assignments and sensitive banking records. A missing authentication check in the view-assign-locker.php page allows unauthenticated attackers to directly access and download complete customer records including full names, email addresses, phone numbers, home addresses, identity documents, and photographs by simply changing a numeric ID parameter in the URL.

Technical details

This is an authentication bypass vulnerability caused by a missing session validation check in the /blms/view-assign-locker.php file. The vulnerable component accepts a GET parameter (ltid) and directly queries the database to render sensitive customer personally identifiable information (PII) without verifying the user's session. While other protected pages in the application implement if(strlen($_SESSION['aid'])==0) guards, this particular page omits the check entirely. The attack requires only network access and no authentication credentials; attackers can enumerate all customer records by incrementing the sequential integer ltid parameter and directly access uploaded identity documents and photographs from unprotected directories (banker/addressproof/ and banker/photo/).

Affected products

  • PHPGurukul Bank Locker Management System 1.0

Timeline

  • 2026-09-13: disclosed
  • 2026-07-31: other: Vulnerability confirmed through source code analysis and live deployment verification

References

Related threats