Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:NPhpgurukul Online Library Management System
APPPhpgurukul3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2025-57119CRITICAL9.8PL ✓same product
Eskalacja uprawnień w Phpgurukul Online Library Management System v.3.0
CVE-2025-57118CRITICAL9.8PL ✓same product
Eskalacja uprawnień w PHPGurukul Online Library Management System v3.0
CVE-2025-7600LOW2.1same product
W systemie PHPGurukul Online Library Management System 3.0 odkryto podatność sklasyfikowaną jako krytyczną. Do...
CVE-2025-7601LOW2.0same product
W PHPGurukul Online Library Management System 3.0 odkryto podatność wpływającą na plik /admin/student-history....
CVE-2025-2093LOW2.3same product
W PHPGurukul Online Library Management System 3.0 odkryto podatność. Dotyczy ona nieznanej funkcjonalności pli...