CVE-2025-45953
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2025-45953 is a newly discovered vulnerability affecting the PHPGurukul Hostel Management System 2.1. Specifically, the issue resides in the "/hostel/change-password.php" file of the user panel's Change Password component. This vulnerability enables an attacker to hijack user sessions due to improper handling of session data, making it exploitable remotely. By exploiting this flaw, an adversary could gain unauthorized access to sensitive user information and potentially execute unauthorized actions within the system. It is crucial for users of this software to apply the necessary security patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.