Cross Site Scripting Vulnerability in Online Exam Mastering System by code-projects
CVE-2025-46173
6.1MEDIUM
Key Information:
- Vendor
code-projects
- Vendor
- CVE Published:
- 27 May 2025
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2025-46173?
The Online Exam Mastering System version 1.0 faces a Cross Site Scripting (XSS) vulnerability. This flaw allows attackers to inject malicious scripts through the name field in the feedback form, potentially compromising user data and session information. Proper input validation and sanitization measures are essential to mitigate this risk and prevent unauthorized script execution.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.