PHPGurukul User Registration and Login Session Hijacking Vulnerability Allowing Account Takeover

Vulnerability

A critical session fixation vulnerability has been identified in PHPGurukul User Registration & Login and User Management System version 3.3. The issue resides in the Change Password component of the user panel, specifically within the '/loginsystem/change-password.php' file. The vulnerability arises from improper handling of session data, which allows for remote session hijacking attacks, leading to unauthorized account access and actions such as password changes.

Impact

Exploitation of this vulnerability allows for session fixation, where an attacker can gain unauthorized access to a victim's account by hijacking their session.

Reproduction

To reproduce this vulnerability, manually set or predict a session ID and send it to the victim. Once the victim logs in using the fixed session ID, the attacker can access the victim's account and change the password.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
1.3
exploitability
7.3
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.