Impact
The vulnerability arises from a lack of proper input sanitization in the feedback.php component of the projectworlds Online Examination System. A malicious user can inject arbitrary JavaScript by altering the Name or Subject parameters, leading to cross‑site scripting. The weakness corresponds to CWE‑79; while CWE‑94 also appears in the metadata, the description does not provide evidence of code execution in a dynamic context. The affected version is 1.0. An attacker who succeeds can hijack user sessions, steal credentials, deface the site, or deploy additional malware.
Affected Systems
The vulnerability affects projectworlds Online Examination System version 1.0. No other versions or patches are referenced in the vendor information. Administrators should verify the installed version and check for any newer releases or vendor advisories.
Risk and Exploitability
The risk is moderate, with a CVSS score of 5.3. No EPSS score is published, so exploitation likelihood is uncertain. The vulnerability is not listed in the CISA KEV catalog. Since the attack vector is remote and the application is publicly accessible, the risk remains significant. The lack of publicly disclosed patch or update amplifies the window of exposure.
OpenCVE Enrichment