CVE Vulnerabilities

CVE-2025-45949

Session Fixation

Published: Apr 28, 2025 | Modified: Apr 30, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account takeover.

Weakness

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Affected Software

Name Vendor Start Version End Version
User_registration_&_login_and_user_management_system Phpgurukul 3.3 (including) 3.3 (including)

Extended Description

Such a scenario is commonly observed when:

Potential Mitigations

References