CVE Vulnerabilities

CVE-2025-45953

Session Fixation

Published: Apr 28, 2025 | Modified: Apr 30, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely

Weakness

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Affected Software

Name Vendor Start Version End Version
Hostel_management_system Phpgurukul 2.1 (including) 2.1 (including)

Extended Description

Such a scenario is commonly observed when:

Potential Mitigations

References