CVE-2025-63713: XSS
Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary web script or HTML via crafted input in the custom test creation feature. The vulnerability exists because the application fails to properly sanitize user-supplied input in test titles and matching pair items before rendering them in the DOM during test execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63713?
CVE-2025-63713 is classified as a high-severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-63713?
To fix CVE-2025-63713, ensure input validation and sanitization are implemented for user-supplied data in the custom test creation feature.
Who is affected by CVE-2025-63713?
CVE-2025-63713 affects users of SourceCodester MatchMaster version 1.0.
How can CVE-2025-63713 be exploited?
CVE-2025-63713 can be exploited by remote attackers injecting arbitrary web scripts or HTML through crafted input.
What are the potential impacts of exploiting CVE-2025-63713?
Exploiting CVE-2025-63713 could allow attackers to execute malicious scripts in the context of the victim's browser.