Junglewise Threat Intelligence

CVE-2025-50492: PHPGurukul e-Diary Management System improper session invalidation

CVE-2025-50492 · Severity: high · CVSS 7.5 · Published 2025-07-28

Vendors: Phpgurukul.

Executive brief

A vulnerability exists in the PHPGurukul e-Diary Management System, a web application used for managing personal or business diaries. The software fails to properly invalidate user sessions when a password is changed. This could allow an unauthorized person to maintain access to an account even after the legitimate owner attempts to secure it, potentially leading to the theft of private diary entries or unauthorized account control.

Technical details

A session management vulnerability exists in PHPGurukul e-Diary Management System v1.0 within the '/edms/change-password.php' component. The application fails to terminate or invalidate existing active sessions upon a password change event. An attacker who has previously obtained a valid session identifier can continue to access the application even after the user updates their credentials. This flaw is categorized as improper session invalidation (related to CWE-20) and can be exploited over the network without specific user interaction, leading to persistent unauthorized access.

Affected products

  • PHPGurukul e-Diary Management System 1.0

Timeline

  • 2025-07-28: advisory: Initial disclosure by NVD/MITRE

References

Related threats