High severity8.8NVD Advisory· Published Nov 10, 2025· Updated Jun 17, 2026
CVE-2025-63712
CVE-2025-63712
Description
Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF protection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)
- cpe:2.3:a:senior-walter:web-based_pharmacy_product_management_system:1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- github.com/floccocam-cpu/CVE-Research-2025/blob/main/CVE-2025-63712/README4.mdnvdExploitThird Party Advisory
- www.sourcecodester.com/php/17883/web-based-product-alert-system.htmlnvdProduct
News mentions
0No linked articles in our index yet.