Unrestricted File Upload in PHPGurukul Bank Locker 1.0 via addressproof
CVE-2026-90519 Published on September 13, 2026

PHPGurukul Bank Locker Management System add-locker-form.php unrestricted upload
A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Types

What is an Unrestricted File Upload Vulnerability?

The software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

CVE-2026-90519 has been classified to as an Unrestricted File Upload vulnerability or weakness.

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-90519 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2026-90519

Want to know whenever a new CVE is published for PHPGurukul Bank Locker Management System? stack.watch will email you.

 

Affected Versions

PHPGurukul Bank Locker Management System Version 1.0 is affected by CVE-2026-90519