PT-2025-46162 · Sourcecodester · Client Database Management System

Published

2025-11-10

·

Updated

2025-11-14

·

CVE-2025-63711

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions SourceCodester Client Database Management System version 1.0
Description A Cross-Site Request Forgery (CSRF) issue exists in the application, potentially allowing an attacker to cause an authenticated administrative user to perform actions without their consent. The application’s user deletion endpoint, such as /superadmin user delete.php, accepts POST requests containing the user id parameter. The endpoint does not enforce request origin or anti-CSRF tokens, and lacks proper authentication/authorization checks and CSRF protections. An attacker can craft a malicious page that triggers deletion when visited by an authenticated administrator, resulting in arbitrary removal of user accounts.
Recommendations Apply appropriate CSRF protections to the /superadmin user delete.php endpoint. Implement request origin validation to ensure requests originate from trusted sources. Enforce anti-CSRF tokens for all state-changing requests, including user deletion. Implement robust authentication and authorization checks to verify user permissions before allowing deletion actions.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-63711

Affected Products

Client Database Management System