Impact
A flaw exists in the host‑management system’s checklogin.php, where changing the ID argument bypasses the intended authentication checks. The deviation allows an attacker to gain unauthorized administrative privileges through remote interaction, potentially exposing sensitive data or enabling further compromise.
Affected Systems
The vulnerability is present in PHPGurukul Hostel Management System 3.0. No additional product or version scope has been listed, so the impact is limited to installations running that specific version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the reported exploit is remotely accessible. With the EPSS score not available and no listing in the CISA KEV catalog, the likelihood of large‑scale exploitation cannot be quantified, but the existence of a public exploit indicates a real threat to affected deployments.
OpenCVE Enrichment