CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-45949

Critical · CVSS 9.8

PHPGurukul User Registration & Login and User Management System — Session Hijacking / Session Fixation (CWE-384)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-384

Description

A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account takeover.

Search profile — drives PoC discovery

Symbols change-password.php/loginsystem/change-password.phpuser panelChange Password componentsession data
Keywords CVE-2025-45949PHPGurukul User Management Systemsession hijackingchange-password.phpaccount takeoverV3.3User Registration Login Management System PoC
Versions: V3.3

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z