CVE-2026-90851
A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.21%
- CWE
- CWE-284, CWE-266
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- PHPGurukul Hostel Management System
Weakness type
Related vulnerabilities
- CVE-2026-65182 — Apache Tomcat: Bypass longest prefix security constraint
- CVE-2026-76607 — Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2
- CVE-2026-54745 — Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true
- CVE-2026-20315 — Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities
- CVE-2026-20192 — Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities
- CVE-2026-77553 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
- CVE-2026-77536 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
- CVE-2026-77534 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f