CVE-2025-1955: code-projects Online Class and Exam Scheduling System profile.php cross site scripting
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Scheduling/scheduling/pages/profile.php. The manipulation of the argument username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1955?
CVE-2025-1955 has been rated as problematic.
Which software is affected by CVE-2025-1955?
CVE-2025-1955 affects the Online Class and Exam Scheduling System 1.0 by code-projects.
What kind of vulnerability is described in CVE-2025-1955?
CVE-2025-1955 describes a cross-site scripting (XSS) vulnerability due to manipulation of the username argument.
How do I fix CVE-2025-1955?
To fix CVE-2025-1955, ensure that all input fields, particularly username, are properly sanitized and validated.
What functionality is impacted by CVE-2025-1955?
CVE-2025-1955 impacts the profile.php page within the Online Class and Exam Scheduling System.