PT-2026-106317 · Phpgurukul · User Registration & Login/User Management System

·

CVE-2026-105703

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

CVSS v2.0

5.8

Média

VetorAV:N/AC:L/Au:M/C:P/I:P/A:P
A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

Exploit

Correção

Incorrect Authorization

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-105703

Produtos afetados

User Registration & Login/User Management System