First published: Mon Mar 17 2025(Updated: )
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Code-projects Online Class and Exam Scheduling System | ||
Online Class And Exam Scheduling System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29427 is classified as a medium severity vulnerability due to its potential for exploitation through Cross Site Scripting.
To fix CVE-2025-29427, sanitize and validate user inputs for the member_first and member_last parameters to prevent XSS attacks.
CVE-2025-29427 affects the Code-projects Online Class and Exam Scheduling System version 1.0.
The risks associated with CVE-2025-29427 include potential data theft, session hijacking, and unauthorized access to user accounts.
Yes, CVE-2025-29427 is an exploitable vulnerability that can be triggered remotely through crafted web requests.