Executive brief
A vulnerability exists in the PHPGurukul Car Rental Project, a web application used for managing vehicle rentals. The software fails to properly clear or refresh user sessions when a password is changed. This could allow an attacker to hijack a user's active session, potentially leading to unauthorized account access and the ability to view or modify customer data.
Technical details
A session management vulnerability (CWE-613) exists in PHPGurukul Car Rental Project v3.0 within the update-password.php component. The application fails to properly invalidate or rotate session identifiers upon sensitive actions like password updates. An attacker can exploit this by fixing or capturing a session ID; if a victim authenticates or continues using the application under that ID, the attacker maintains access even after credentials have been changed. This requires some user interaction (UI:R) to establish the initial session state but allows for high confidentiality impact through session hijacking.
Affected products
- PHPGurukul Car Rental Project 3.0
Timeline
- 2025-07-28: advisory: NVD publication date