CVE-2025-45949
Critical · CVSS 9.8PHPGurukul User Registration & Login and User Management System — Session Hijacking / Session Fixation (CWE-384)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-384
Description
A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account takeover.
Search profile — drives PoC discovery
Symbols change-password.php/loginsystem/change-password.phpuser panelChange Password componentsession data
Keywords CVE-2025-45949PHPGurukul User Management Systemsession hijackingchange-password.phpaccount takeoverV3.3User Registration Login Management System PoC
Versions: V3.3
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z