---
id: CVE-2026-90519
title: A weakness has been identified in PHPGurukul Bank Locker Management System 1.0
summary: >-
  A weakness has been identified in PHPGurukul Bank Locker Management System
  1.0. Affected is an unknown function of the file
  /blms/banker/add-locker-form.php. This manipulation of the argument
  addressproof causes unrestricted upload. Remo…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-284
  - CWE-434
vendor: PHPGurukul
product: Bank Locker Management System
affected:
  - bank_locker_management_system 1.0
published: '2026-09-13'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T15:17:28.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90519'
references:
  - url: 'https://github.com/wakakakaaaaha/vuln/issues/5'
    label: cna@vuldb.com
  - url: 'https://phpgurukul.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90519'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/912224'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403106'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403106/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00366
epssPercentile: 0.27663
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T13:42:27.322018Z'
ingestedAt: '2026-09-14T15:23:07.470Z'
---

## Overview

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
