CVE-2025-29427: XSS
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the memberfirst and memberlast parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29427?
CVE-2025-29427 is classified as a medium severity vulnerability due to its potential for exploitation through Cross Site Scripting.
How do I fix CVE-2025-29427?
To fix CVE-2025-29427, sanitize and validate user inputs for the member_first and member_last parameters to prevent XSS attacks.
What systems are affected by CVE-2025-29427?
CVE-2025-29427 affects the Code-projects Online Class and Exam Scheduling System version 1.0.
What are the risks associated with CVE-2025-29427?
The risks associated with CVE-2025-29427 include potential data theft, session hijacking, and unauthorized access to user accounts.
Is CVE-2025-29427 exploitable remotely?
Yes, CVE-2025-29427 is an exploitable vulnerability that can be triggered remotely through crafted web requests.