Executive brief
The PHPGurukul Bank Locker Management System is a PHP-based web application used to manage customer locker assignments and sensitive banking records. A missing authentication check in the view-assign-locker.php page allows unauthenticated attackers to directly access and download complete customer records including full names, email addresses, phone numbers, home addresses, identity documents, and photographs by simply changing a numeric ID parameter in the URL.
Technical details
This is an authentication bypass vulnerability caused by a missing session validation check in the /blms/view-assign-locker.php file. The vulnerable component accepts a GET parameter (ltid) and directly queries the database to render sensitive customer personally identifiable information (PII) without verifying the user's session. While other protected pages in the application implement if(strlen($_SESSION['aid'])==0) guards, this particular page omits the check entirely. The attack requires only network access and no authentication credentials; attackers can enumerate all customer records by incrementing the sequential integer ltid parameter and directly access uploaded identity documents and photographs from unprotected directories (banker/addressproof/ and banker/photo/).
Affected products
- PHPGurukul Bank Locker Management System 1.0
Timeline
- 2026-09-13: disclosed
- 2026-07-31: other: Vulnerability confirmed through source code analysis and live deployment verification