CVE-2025-28121
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Apr 21, 2025
Updated: Apr 24, 2025
CWE ID 79
Summary
CVE-2025-28121 is a newly identified vulnerability affecting the code-projects Online Exam Mastering System 1.0. This issue permits remote attackers to execute arbitrary code through a Cross-Site Scripting (XSS) vulnerability located in the "feedback.php" file. The vulnerability can be exploited by injecting malicious scripts into the "q" parameter, leading to potential data theft or unauthorized system access. System administrators are advised to apply the necessary security patches as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Code Projects