CVE-2025-63717: Mayurik Pet Grooming Management Software

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie restrictions, allowing attackers to trick authenticated users into unknowingly changing their passwords.

Affected products

  • Mayurik Pet Grooming Management Software: version 1.0 only

Published 2025-11-07. Last modified 2026-06-17.