Beveiligingsadvies

CVE-2025-45949

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-04-28 00:00:00
Laatst bijgewerkt 2026-07-25 01:10:28
Toegewezen door mitre
CVSS-score 9.8
Status PUBLISHED

Beschrijving

A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account takeover.