Impact
A flaw in PHPGurukul Bank Locker Management System 1.0 allows an attacker to abuse the ltid parameter in the view-assign-locker.php page to bypass the application’s authorization checks. Manipulating this argument triggers CWE-285: Authorization Bypass Through User Controlled Key and CWE-639: Permission Check Failure, permitting an unauthenticated or improperly authorized user to view or modify locker assignments without permission. The vulnerability can be triggered from a remote web request and a publicly available exploit has been reported, meaning the attack can be initiated outside the local environment.
Affected Systems
PHPGurukul Bank Locker Management System version 1.0 is affected when accessing the /blms/view-assign-locker.php endpoint. The specific function that processes the ltid argument is vulnerable; it is unknown whether newer versions contain the same issue.
Risk and Exploitability
The CVSS score of 6.9 reflects moderate severity, while the EPSS score of <1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA KEV catalog, but the existence of a public exploit suggests that attackers could remotely craft a ltid value to bypass security controls. Successful exploitation would grant unauthorized access to locker data, potentially compromising confidentiality, integrity, and availability of the system.
OpenCVE Enrichment