Impact
A vulnerability exists in the /admin/remove‑user.php endpoint of code‑projects Assessment Management version 1.0. By manipulating the ID query argument, an attacker can cause the application to echo back unescaped input, resulting in reflected cross‑site scripting that can run arbitrary scripts in the victim’s browser. The flaw can be triggered remotely via a crafted HTTP GET request and does not require authentication.
Affected Systems
Only the code‑projects Assessment Management product, specifically version 1.0, is affected. Any installation exposing the /admin/remove‑user.php path without the vendor fix remains vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 5.3 indicates a moderate impact. With an EPSS of less than 1 % and no listing in the CISA KEV catalog, the likelihood of exploitation at present is low. Attackers can reach the vulnerable endpoint from any network location that can reach the web application and supply a malicious ID value to induce the XSS flaw.
OpenCVE Enrichment