Unrated severityNVD Advisory· Published Nov 10, 2025· Updated Nov 18, 2025
CVE-2025-63712
CVE-2025-63712
Description
Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF protection.
Affected products
2- SourceCodester/Product Expiry Management Systemdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.