Impact
The vulnerability is a loss of proper access controls in the file sidebar.php of the PHPGurukul Bank Locker Management System. By manipulating the UserType argument, an attacker can bypass authentication checks and gain unauthorized access to privileged functions. The weakness is categorized as CWE‑266 (Improper Privilege Management) and CWE‑284 (Improper Access Control).
Affected Systems
PHPGurukul Bank Locker Management System version 1.0 is affected. No mitigations are indicated for earlier or newer versions; the vendor is PHPGurukul.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the vulnerability can be exploited remotely via crafted requests to sidebar.php. An EPSS score of less than 1% suggests a low probability of exploitation, but the presence of a publicly released exploit indicates that an attacker could opportunistically target exposed instances. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment