CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-45953

Critical · CVSS 9.1

PHPGurukul Hostel Management System — Session Hijacking (CWE-384)

CVSS
9.1
nvd
EPSS
KEV
No
Class
other
CWE-384

Description

A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely

Search profile — drives PoC discovery

Symbols /hostel/change-password.phpchange-passworduser panelsession data
Keywords CVE-2025-45953PHPGurukul Hostel Management Systemsession hijackingchange-password.phphostel managementCWE-384session fixationremote exploit
Versions: 2.1

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z