CVE-2025-45949: Critical severity Phpgurukul User Registration & Login and User Management System vulnerability
A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account takeover.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45949?
CVE-2025-45949 is classified as a critical vulnerability due to its potential for session hijacking, which can lead to unauthorized access to user accounts.
How do I fix CVE-2025-45949?
To fix CVE-2025-45949, ensure that session data is handled securely by implementing proper session management practices in the affected component.
What software is affected by CVE-2025-45949?
CVE-2025-45949 affects version 3.3 of the PHPGurukul User Registration & Login and User Management System.
Can CVE-2025-45949 be exploited remotely?
Yes, CVE-2025-45949 can be exploited remotely, allowing attackers to hijack user sessions over the internet.
What components of the PHPGurukul system are vulnerable in CVE-2025-45949?
The vulnerability in CVE-2025-45949 specifically affects the Change Password component located in the /loginsystem/change-password.php file.