CVE-2025-63717

The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie restrictions, allowing attackers to trick authenticated users into unknowingly changing their passwords.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mayurik:pet_grooming_management_software:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-07 19:16

Updated : 2025-11-17 18:40


NVD link : CVE-2025-63717

Mitre link : CVE-2025-63717

CVE.ORG link : CVE-2025-63717


JSON object : View

Products Affected

mayurik

  • pet_grooming_management_software
CWE
CWE-352

Cross-Site Request Forgery (CSRF)