CVE-2025-28121
MEDIUMCVSS 6.1/10EPSS 0.72%
Last modified
CVE-2025-28121 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Code-Projects | Online Exam Mastering System | 1.0 |
References
- https://github.com/pruthuraut/CVE-2025-28121Exploit, Third Party Advisory
- https://github.com/pruthuraut/CVE-2025-28121Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-28121?
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.
How severe is CVE-2025-28121?
CVE-2025-28121 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 0.72% probability of exploitation in the next 30 days.
How do I fix CVE-2025-28121?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-28101An arbitrary file deletion vulnerability in the /post/{postT…6.5
- CVE-2025-28102A cross-site scripting (XSS) vulnerability in flaskBlog v2.6…6.1
- CVE-2025-28103Incorrect access control in laskBlog v2.6.1 allows attackers…6.4
- CVE-2025-28104Incorrect access control in laskBlog v2.6.1 allows attackers…9.1
- CVE-2025-2811A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL…6.9
- CVE-2025-2812Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2025-28128An issue in Mytel Telecom Online Account System v1.0 allows …7
- CVE-2025-28129Phpgurukul Hostel Management System 2.1 is vulnerable to cli…5.4
- CVE-2025-2813An unauthenticated remote attacker can cause a Denial of Ser…7.5
- CVE-2025-28131A Broken Access Control vulnerability in Nagios Network Anal…4.6
- CVE-2025-28132A session management flaw in Nagios Network Analyzer 2024R1.…4.6
- CVE-2025-28135TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain …7.5
Are you affected by CVE-2025-28121?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
