CVE-2025-63712HIGH 8.8EPSS p7.9%

CVE-2025-63712CVE-2025-63712

Description

Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF protection.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.18% probability of exploitation · percentile 7.9% · 2026-06-18T12:00:27Z
Published2025-11-10
Last modified2025-11-18

Underlying weaknesses· 1

CWE-352

References

  1. https://github.com/floccocam-cpu/CVE-Research-2025/blob/main/CVE-2025-63712/README4.md
  2. https://www.sourcecodester.com/php/17883/web-based-product-alert-system.html

1

TypeTargetConfidenceTier
WeaknessCross-Site Request Forgery (CSRF)cwe-3520%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-3770
CVE
CVE-2025-10595
CVE
CVE-2025-10627
CVE
CVE-2025-4282
CVE
CVE-2026-3762
CVE
CVE-2025-13468
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.