Description
A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard Page. The manipulation of the argument ID results in missing authorization. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-06-04
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from a missing authorization check on the Admin Dashboard index.php page. When an attacker manipulates the ID argument, the system fails to verify that the caller has the appropriate rights, effectively allowing unauthorized use of administrative functionality.

Affected Systems

The flaw is present in the LakshayD02 Hostel-Management-System-PHP application. No versioning exists, and the affected releases are unknown, so all deployments of this project are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, yet the public exploit and remote attack surface raise concern. An attacker can craft a request to index.php with a modified ID parameter from outside the network and gain unauthorized access.

Generated by OpenCVE AI on June 4, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Add authorization checks to verify that the administrator’s session is valid and that the requested ID belongs to a resource the user can access.
  • Validate the ID parameter and reject any values that are not permitted for the current user role.
  • Apply any vendor‑issued patch or update as soon as the maintainer addresses the issue.
  • Monitor application logs for anomalous access to index.php and restrict access to the admin interface via network controls.

Generated by OpenCVE AI on June 4, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard Page. The manipulation of the argument ID results in missing authorization. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Title LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization
First Time appeared Lakshayd02
Lakshayd02 hostel-management-system-php
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:lakshayd02:hostel-management-system-php:*:*:*:*:*:*:*:*
Vendors & Products Lakshayd02
Lakshayd02 hostel-management-system-php
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Lakshayd02 Hostel-management-system-php
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-04T15:56:30.145Z

Reserved: 2026-06-04T05:46:21.294Z

Link: CVE-2026-10815

cve-icon Vulnrichment

Updated: 2026-06-04T15:55:15.608Z

cve-icon NVD

Status : Deferred

Published: 2026-06-04T16:16:33.347

Modified: 2026-06-04T16:32:40.690

Link: CVE-2026-10815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-04T16:30:06Z

Weaknesses