Executive brief
PHPGurukul Hostel Management System is a web-based application for managing hostel operations, including student records, room allocations, and administrative functions. The system fails to properly verify that a logged-in user is actually an administrator before granting access to sensitive administrative pages. This means any student who logs in can bypass authentication and gain full access to administrative features, including the ability to view, modify, or delete student records, room assignments, complaints, and access logs.
Technical details
The vulnerability is a broken access control flaw (CWE-269/CWE-284) in the /admin/includes/checklogin.php authorization function. The root cause is that both student and administrator login flows assign a numeric user ID to the same $_SESSION['id'] variable, and the check_login() function only verifies that this session variable is non-empty—it does not verify the user's role. A remote authenticated student can directly request any administrative page (e.g., /admin/dashboard.php, /admin/manage-students.php) and the application treats the student session as having administrator privileges. The attack requires authentication as a student but no administrator credentials or user interaction. An attacker can perform administrative actions including viewing/modifying/deleting student records, managing rooms and courses, and accessing audit logs. No patch has been identified in the advisory; remediation requires code changes to use separate session namespaces for students and admins, and enforcing a server-side role check on every protected page.
Affected products
- PHPGurukul Hostel Management System 3.0
Timeline
- 2026-08-13: disclosed: Vulnerability disclosed on GitHub
- 2026-09-15: advisory: CVE-2026-90851 published