Impact
The flaw exists in an unspecified function of SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0 and permits cross‑site request forgery. An attacker can trick a victim’s browser into sending a forged request that performs a state‑changing operation controlled by the attacker. The underlying weakness involves inadequate authorisation checks (CWE‑862) and the absence of CSRF protection mechanisms (CWE‑352). The impact is that the attacker can perform actions on behalf of the victim without their knowledge, potentially leading to privilege escalation or data manipulation.
Affected Systems
SourceCodester’s Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0 is affected. No additional versions or product variants are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Exploitation is possible remotely, as the vulnerability can be triggered via normal web traffic. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not a widely known exploited flaw at present. However, public exploits have been released and could be used by attackers who exploit the CSRF flaw by loading the target site in the victim’s browser and leveraging the vulnerable function.
OpenCVE Enrichment