Permissive Cross-Domain Policy Vulnerability in Mindskip xzs-mysql
CVE-2025-1083

2.3LOW

Key Information:

Vendor

Mindskip

Vendor
CVE Published:
6 February 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-1083?

A vulnerability has been identified in the Mindskip xzs-mysql 3.9.0 component, specifically within its CORS Handler functionality. This flaw allows the establishment of a permissive cross-domain policy, potentially exposing the system to various security risks from untrusted domains. An attacker could exploit this vulnerability remotely, although the complexity and difficulty of executing the attack are relatively high. Despite the disclosure of this exploit to the public and attempts to contact the vendor for a response, there has been no communication from their side regarding mitigations or fixes.

Affected Version(s)

xzs-mysql 学之思开源考试系统 3.9.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

.
CVE-2025-1083 : Permissive Cross-Domain Policy Vulnerability in Mindskip xzs-mysql