CVE-2025-63712: Senior-Walter Web-Based Pharmacy Product Management System
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF protection.
Affected products
- Senior-Walter Web-Based Pharmacy Product Management System: version 1.0 only
Published 2025-11-10. Last modified 2026-06-17.