CVE-2025-50486: High severity Phpgurukul Car Rental Project vulnerability
Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50486?
CVE-2025-50486 has a medium severity rating due to the potential for session hijacking attacks.
How do I fix CVE-2025-50486?
To fix CVE-2025-50486, ensure proper session management practices by implementing secure session invalidation methods after password updates.
Who is affected by CVE-2025-50486?
CVE-2025-50486 affects users of the PHPGurukul Car Rental Project v3.0 and potentially other related applications with similar vulnerabilities.
What type of attack does CVE-2025-50486 enable?
CVE-2025-50486 enables attackers to perform session hijacking attacks due to improper session invalidation.
Is CVE-2025-50486 present in other versions of the software?
CVE-2025-50486 is specifically identified in version 3.0 of the PHPGurukul Car Rental Project, so other versions should be assessed separately.