Junglewise Threat Intelligence

CVE-2025-50491: PHPGurukul Bank Locker Management System session hijacking in change-password.php

CVE-2025-50491 · Severity: high · CVSS 7.1 · Published 2025-07-28

Technologies: Phpgurukul Bank Locker Management System. Vendors: Phpgurukul.

Executive brief

A security flaw exists in the PHPGurukul Bank Locker Management System, a software platform used to manage bank safe deposit boxes. An attacker can exploit this vulnerability to take over a legitimate user's session, potentially gaining unauthorized access to sensitive banking management functions. This could allow an unauthorized individual to change passwords or access private locker information, compromising the integrity of the bank's management operations.

Technical details

A vulnerability classified as Insufficient Session Expiration (CWE-613) exists in the '/banker/change-password.php' component of PHPGurukul Bank Locker Management System v1.0. The flaw stems from improper session invalidation and handling, which allows an attacker to perform a session fixation or hijacking attack. By setting or capturing a session ID before a victim authenticates, the attacker can maintain an active, authorized session once the victim logs in. This enables the attacker to gain unauthorized remote access to the banker's panel and perform administrative actions, such as changing account credentials. The attack requires minimal user interaction and is reachable over the network.

Affected products

  • PHPGurukul Bank Locker Management System 1.0

Timeline

  • 2025-07-28: advisory: Initial NVD publication date
  • 2025-07-28: disclosed: Vulnerability discovered by Vasil VK

References

Related threats