CVE-2025-7756

MEDIUM

code-projects E-Commerce Site 1.0 - CSRF

Title source: llm

Description

A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 12.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-862 CWE-352
Status published

Affected Products (1)

fabian/e-commerce_site

Timeline

Published Jul 17, 2025
Tracked Since Feb 18, 2026