Executive brief
The PHPGurukul Student Result Management System, a platform used to manage and display academic results, contains a security flaw in its password management component. This vulnerability allows an attacker to take over a user's session, potentially gaining unauthorized access to student or administrative accounts. This could lead to the unauthorized viewing or modification of sensitive academic records and personal information.
Technical details
A session hijacking vulnerability exists in PHPGurukul Student Result Management System v2.0 within the /srms/change-password.php component. The application fails to properly invalidate or regenerate session identifiers during sensitive operations or authentication state changes. An attacker can exploit this by fixing a known session ID or capturing an active session token to gain unauthorized remote access to a victim's account. Once the session is hijacked, the attacker can perform actions on behalf of the user, including changing the account password. The vulnerability is classified as Broken Access Control (CWE-20/CWE-384).
Affected products
- PHPGurukul Student Result Management System 2.0
Timeline
- 2025-07-28: disclosed
- 2025-07-28: advisory