Critical severity9.8NVD Advisory· Published Apr 28, 2025· Updated Jul 5, 2026
CVE-2025-45949
CVE-2025-45949
Description
A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:phpgurukul:user_registration_\&_login_and_user_management_system:3.3:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:phpgurukul:user_registration_\&_login_and_user_management_system:3.3:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: = V3.3
Patches
Vulnerability mechanics
References
1- github.com/VasilVK/CVE/blob/main/CVE-2025-45949/README.MDnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.