CVE-2025-13063

HIGH

DinukaNavaratna Dee Store 1.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. The attack may be performed from remote. The exploit has been published and may be used. Multiple endpoints are affected.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.332189
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.332189
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.682708

Scores

CVSS v3 7.3
EPSS 0.0031
EPSS Percentile 22.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-862 CWE-863
Status published
Products (1)
DinukaNavaratna/Dee Store 1.0
Published Nov 12, 2025
Tracked Since Feb 18, 2026