MEDIUM
CVE-2026-90518
CVSS
6.3
Description
A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Weakness (CWE)
CWE-266
Incorrect Privilege Assignment
CWE-284
Improper Access Control
EPSS Score
0.21%
Probability of exploitation in next 30 days
11.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.