Cross-Site Request Forgery in SourceCodester Simple Public Chat Room
CVE-2025-63710

6.5MEDIUM

Key Information:

Vendor
CVE Published:
10 November 2025

What is CVE-2025-63710?

The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is susceptible to Cross-Site Request Forgery (CSRF). The application lacks crucial CSRF protection mechanisms, such as tokens, nonces, or same-site cookie restrictions. This flaw enables an attacker to craft a malicious HTML page that, when accessed by an authenticated user, can trigger an unauthorized POST request to the vulnerable endpoint. As a result, actions can be performed on behalf of the user, including sending unintended messages within any chat room hosted by the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.