Stored Cross-Site Scripting in Kashipara Computer Base Test
CVE-2025-56697

6.1MEDIUM

Key Information:

Vendor

Kashipara

Vendor
CVE Published:
16 September 2025

What is CVE-2025-56697?

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Kashipara Computer Base Test product. This flaw allows attackers to inject harmful scripts through the smyFeedbacks POST parameter located in the /users/adminpanel/admin/home.php?page=feedbacks file. As a result, malicious users may execute unauthorized scripts in the context of legitimate user sessions, potentially compromising sensitive data and leading to further exploitation. This highlights the necessity for robust input validation and security measures to protect against such vulnerabilities.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.