Impact
A flaw in the admin/view-users.php script of code-projects Assessment Management allows an attacker to inject arbitrary JavaScript by manipulating the User parameter. The vulnerability is a classic cross-site scripting (CWE‑79). An exploit can execute malicious script in the context of any user who visits the page, potentially enabling unauthorized client‑side attacks.
Affected Systems
Only code‑projects Assessment Management is listed as affected. No version number is specified, so the flaw could apply to any release until a patch is issued.
Risk and Exploitability
The CVSS score of 4.8 indicates a low severity, while the EPSS score of <1% reflects a very low historical exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but it is publicly disclosed and can be triggered remotely by sending a crafted request that modifies the User query string. Because the flaw resides in a server‑generated page, it can be exploited without requiring privileged access on the host.
OpenCVE Enrichment