Junglewise Threat Intelligence

CVE-2025-50486: PHPGurukul Car Rental Project improper session invalidation in update-password.php

CVE-2025-50486 · Severity: high · CVSS 7.1 · Published 2025-07-28

Vendors: Phpgurukul.

Executive brief

A vulnerability exists in the PHPGurukul Car Rental Project, a web application used for managing vehicle rentals. The software fails to properly clear or refresh user sessions when a password is changed. This could allow an attacker to hijack a user's active session, potentially leading to unauthorized account access and the ability to view or modify customer data.

Technical details

A session management vulnerability (CWE-613) exists in PHPGurukul Car Rental Project v3.0 within the update-password.php component. The application fails to properly invalidate or rotate session identifiers upon sensitive actions like password updates. An attacker can exploit this by fixing or capturing a session ID; if a victim authenticates or continues using the application under that ID, the attacker maintains access even after credentials have been changed. This requires some user interaction (UI:R) to establish the initial session state but allows for high confidentiality impact through session hijacking.

Affected products

  • PHPGurukul Car Rental Project 3.0

Timeline

  • 2025-07-28: advisory: NVD publication date

References

Related threats