Executive brief
A vulnerability exists in the PHPGurukul Doctor Appointment Management System, a platform used for managing medical appointments. The software fails to properly refresh or invalidate user sessions when a password is changed. This could allow an attacker to maintain unauthorized access to a doctor's account even after security credentials have been updated, potentially leading to the compromise of sensitive medical scheduling data.
Technical details
A Broken Access Control vulnerability exists in PHPGurukul Doctor Appointment Management System v1.0.0 within the /doctor/change-password.php component. The application fails to properly invalidate existing sessions or implement secure session fixation protections during sensitive operations. An attacker can exploit this by fixing a known session ID or capturing a session token; because the system does not refresh the session identifier upon authentication or password changes, the attacker can maintain persistent, unauthorized access to the victim's account. This allows for session hijacking and subsequent account takeover.
Affected products
- PHPGurukul Doctor Appointment Management System 1.0.0
Timeline
- 2025-07-28: advisory: Initial NVD publication
- 2025-07-28: disclosed: Vulnerability discovered by Vasil VK