---
id: CVE-2026-90518
title: >-
  A security flaw has been discovered in PHPGurukul Bank Locker Management
  System 1.0
summary: >-
  A security flaw has been discovered in PHPGurukul Bank Locker Management
  System 1.0. This impacts an unknown function of the file sidebar.php. The
  manipulation of the argument UserType results in improper access controls. The
  attack may …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-266
  - CWE-284
vendor: PHPGurukul
product: Bank Locker Management System
affected:
  - bank_locker_management_system 1.0
published: '2026-09-13'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:56:48.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90518'
references:
  - url: 'https://github.com/wakakakaaaaha/vuln/issues/3'
    label: cna@vuldb.com
  - url: 'https://phpgurukul.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90518'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/912176'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403105'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403105/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T15:29:59.232116Z'
ingestedAt: '2026-09-14T15:17:43.208Z'
epss: 0.00366
epssPercentile: 0.27664
---

## Overview

A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
