Permissive Cross-Domain Policy Vulnerability in Mindskip xzs-mysql
CVE-2025-1083
Key Information:
- Vendor
Mindskip
- Status
- Vendor
- CVE Published:
- 6 February 2025
Badges
What is CVE-2025-1083?
A vulnerability has been identified in the Mindskip xzs-mysql 3.9.0 component, specifically within its CORS Handler functionality. This flaw allows the establishment of a permissive cross-domain policy, potentially exposing the system to various security risks from untrusted domains. An attacker could exploit this vulnerability remotely, although the complexity and difficulty of executing the attack are relatively high. Despite the disclosure of this exploit to the public and attempts to contact the vendor for a response, there has been no communication from their side regarding mitigations or fixes.
Affected Version(s)
xzs-mysql 学之思开源考试系统 3.9.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published