PHPGurukul Online Library Management System Session Hijacking Vulnerability

Vulnerability

A session hijacking vulnerability has been identified in PHPGurukul Online Library Management System version 3.0. The issue arises from improper session invalidation in the Change Password component, located in the user panel. This flaw allows attackers to intercept and misuse session tokens, gaining unauthorized access to user accounts.

Impact

Exploitation of this vulnerability allows for session hijacking, where an attacker can gain unauthorized access to a user's account and perform actions on their behalf, such as changing the account password.

Reproduction

To reproduce this vulnerability, navigate to the Change Password component in the user panel. Observe the session handling process, then inject a known session ID by setting a predictable or captured session token in the browser before logging in. Once the victim logs in with the injected session ID, the attacker can access the victim's account and change the password.

Added: Jul 28, 2025, 6:28 PM
Updated: Jul 28, 2025, 6:28 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.3
exploitability
7.9
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.