Executive brief
PHPGurukul Online Course Registration is a web application used to manage student enrollments and course data. A security flaw in the password change component allows an attacker to take over a user's active session. This could lead to unauthorized access to student accounts, allowing attackers to view personal information or modify account credentials.
Technical details
A session fixation vulnerability exists in PHPGurukul Online Course Registration v3.1 within the /crm/change-password.php (also referenced as /onlinecourse/change-password.php) component. The application fails to properly invalidate or regenerate session identifiers during sensitive operations or authentication transitions. An attacker can pre-set a known session ID in a victim's browser; once the victim authenticates, the attacker can use the fixed session ID to gain unauthorized remote access to the account. This allows for full session hijacking and subsequent account takeover.
Affected products
- PHPGurukul Online Course Registration 3.1
Timeline
- 2025-07-28: advisory: NVD publication date
- 2025-07-01: disclosed: Reported discovery by Vasil VK