PT-2025-45479 · Sourcecodester · Pet Grooming Management

CVE-2025-63717

·

Publicado

2025-11-07

·

Atualizado

2025-11-07

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Pet Grooming Management Software version 1.0
Description The application lacks sufficient anti-CSRF protections, such as anti-CSRF tokens or same-site cookie restrictions. This allows attackers to potentially trick authenticated users into unintentionally changing their passwords. The vulnerable functionality is located at the /pet grooming/admin/change pass.php API endpoint. An attacker could craft a malicious request that, when triggered by an authenticated user, would execute the changePassword() function and alter the user's password.
Recommendations Implement anti-CSRF tokens on the /pet grooming/admin/change pass.php endpoint. Enable same-site cookie restrictions to mitigate the risk of CSRF attacks.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-63717

Produtos afetados

Pet Grooming Management