Executive brief
PHPGurukul Bank Locker Management System is a PHP-based application used to manage bank safety deposit boxes. A broken access control flaw allows authenticated sub-admin users to escalate their privileges by bypassing role-based restrictions in administrative functions, potentially gaining unauthorized access to sensitive banking operations and customer data.
Technical details
The vulnerability is a broken access control issue (CWE-639) in the Bank Locker Management System version 1.0, specifically in the file sidebar.php and related endpoints such as /banker/manage-subadmins.php. The flaw stems from missing server-side validation of the UserType parameter, allowing an authenticated attacker to manipulate role checks. An attacker with sub-admin credentials can craft requests to bypass authorization controls and perform administrative actions, such as creating or modifying user roles. The attack requires network access and valid authentication but no additional user interaction. A public exploit has been released and the vulnerability may be exploited in the wild. No patch information is currently available.
Affected products
- PHPGurukul Bank Locker Management System 1.0
Timeline
- 2026-09-13: disclosed
- 2026-09-13: other: Public exploit released