---
id: CVE-2026-105703
title: >-
  A vulnerability was determined in PHPGurukul User Registration & Login and
  User Management System 3.3
summary: >-
  A vulnerability was determined in PHPGurukul User Registration & Login and
  User Management System 3.3. The impacted element is an unknown function of the
  file loginsystem/admin/change-password.php of the component Change Password
  Handler…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-285
  - CWE-863
vendor: PHPGurukul
product: User Registration & Login and User Management System
affected:
  - user_registration_login_and_user_management_system 3.3
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T04:18:05.587'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105703'
references:
  - url: 'https://github.com/CyberShailendra1/phpgurukul-change-password-broken-auth'
    label: cna@vuldb.com
  - url: 'https://phpgurukul.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-105703'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/992049'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413696'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413696/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T05:47:09.321Z'
---

## Overview

A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
