Junglewise Threat Intelligence

CVE-2025-50489: PHPGurukul Student Result Management System session hijacking in change-password.php

CVE-2025-50489 · Severity: high · CVSS 7.5 · Published 2025-07-28

Vendors: Phpgurukul.

Executive brief

The PHPGurukul Student Result Management System, a platform used to manage and display academic results, contains a security flaw in its password management component. This vulnerability allows an attacker to take over a user's session, potentially gaining unauthorized access to student or administrative accounts. This could lead to the unauthorized viewing or modification of sensitive academic records and personal information.

Technical details

A session hijacking vulnerability exists in PHPGurukul Student Result Management System v2.0 within the /srms/change-password.php component. The application fails to properly invalidate or regenerate session identifiers during sensitive operations or authentication state changes. An attacker can exploit this by fixing a known session ID or capturing an active session token to gain unauthorized remote access to a victim's account. Once the session is hijacked, the attacker can perform actions on behalf of the user, including changing the account password. The vulnerability is classified as Broken Access Control (CWE-20/CWE-384).

Affected products

  • PHPGurukul Student Result Management System 2.0

Timeline

  • 2025-07-28: disclosed
  • 2025-07-28: advisory

References

Related threats