CVE-2025-50491: High severity Phpgurukul Bank Locker Management System vulnerability
Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50491?
CVE-2025-50491 is classified as a medium severity vulnerability due to the potential for session hijacking attacks.
How do I fix CVE-2025-50491?
To fix CVE-2025-50491, ensure proper session invalidation by implementing secure logout mechanisms and session management practices.
What systems are affected by CVE-2025-50491?
CVE-2025-50491 affects PHPGurukul Bank Locker Management System version 1.0.
What is the impact of CVE-2025-50491?
The impact of CVE-2025-50491 includes unauthorized access to user accounts through session hijacking.
How can I verify if my installation is vulnerable to CVE-2025-50491?
You can verify if your installation is vulnerable to CVE-2025-50491 by checking for improper session handling in the /banker/change-password.php component.