CVE-2026-105703: PHPGurukul User Registration & Login and User Management System Change Password change-password.php authorization
A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires high privileges (PR:H). Exploitation is remote and does not require user interaction.
Which deployments are known to be affected?
The affected product is PHPGurukul User Registration & Login and User Management System version 3.3. The issue is associated with the admin change-password.php endpoint and its handling of the currentpassword argument.
Is exploit code available?
Yes. The exploit has been publicly disclosed and may be used by attackers.