CVE-2025-29427

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Mar 17, 2025
Updated: Mar 28, 2025
CWE ID 80

Summary

CVE-2025-29427 is a Cross Site Scripting (XSS) vulnerability affecting version 1.0 of the Code-projects Online Class and Exam Scheduling System. The weakness lies in the profile.php file, which can be exploited through maliciously crafted input in the member_first and member_last parameters. Successful attacks could result in unauthorized script execution within a user's browser, potentially leading to information disclosure or unauthorized actions on the affected system. It is essential that users and administrators of this platform apply the necessary patches or updates to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Online Class And Exam Scheduling System

Affected Vendors

  • Code Projects