CVE-2025-63716 describes a Cross-Site Request Forgery (CSRF) vulnerability in SourceCodester Leads Manager Tool v1.0, affecting the rems leads_manager_tool. This medium-severity flaw (CVSS 6.5) allows unauthenticated attackers to perform unauthorized state-changing operations due to the application's lack of CSRF protection mechanisms. While the vulnerability has a low EPSS score and no known active exploitation, public exploits, or community discussion, its presence could lead to unauthorized data modification or integrity issues.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:rems:leads_manager_tool:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.