CVE-2025-45953
Critical · CVSS 9.1PHPGurukul Hostel Management System — Session Hijacking (CWE-384)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-384
Description
A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely
Search profile — drives PoC discovery
Symbols /hostel/change-password.phpchange-passworduser panelsession data
Keywords CVE-2025-45953PHPGurukul Hostel Management Systemsession hijackingchange-password.phphostel managementCWE-384session fixationremote exploit
Versions: 2.1
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z