Impact
The vulnerability arises from a missing authorization check on the Admin Dashboard index.php page. When an attacker manipulates the ID argument, the system fails to verify that the caller has the appropriate rights, effectively allowing unauthorized use of administrative functionality.
Affected Systems
The flaw is present in the LakshayD02 Hostel-Management-System-PHP application. No versioning exists, and the affected releases are unknown, so all deployments of this project are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, yet the public exploit and remote attack surface raise concern. An attacker can craft a request to index.php with a modified ID parameter from outside the network and gain unauthorized access.
OpenCVE Enrichment