CVE-2025-50484: High severity Phpgurukul Small CRM vulnerability
Published Jul 28, 2025
·Updated
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.
Affected Software
2 affected components
Phpgurukul Small CRM
Phpgurukul Small CRM=3.0
Event History
Jul 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50484?
CVE-2025-50484 is considered a high severity vulnerability due to its potential for session hijacking attacks.
2
How do I fix CVE-2025-50484?
To fix CVE-2025-50484, ensure proper session invalidation mechanisms are implemented in the /crm/change-password.php file.
3
What type of attack can be executed via CVE-2025-50484?
CVE-2025-50484 allows attackers to execute a session hijacking attack.
4
Which component is affected by CVE-2025-50484?
CVE-2025-50484 affects the /crm/change-password.php component of PHPGurukul Small CRM v3.0.
5
What software is vulnerable to CVE-2025-50484?
PHPGurukul Small CRM v3.0 is the software version vulnerable to CVE-2025-50484.