Lakshayd02 · Hostel-Management-System-Php · CVE-2026-10815
**Name of the Vulnerable Software and Affected Versions**
LakshayD02 Hostel-Management-System-PHP versions up to f87e67c283bab6f718faf2fec6ae39a13bd7036b
**Description**
An authorization bypass exists in the Admin Dashboard Page component within the 'hostel/index.php' file. A remote attacker can exploit this by manipulating the `ID` argument, leading to a lack of proper authorization during processing.
**Recommendations**
As a temporary mitigation, restrict access to the 'hostel/index.php' file or avoid using the `ID` argument in that endpoint until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.