Impact
The vulnerability resides in manage_subjects.php and allows an attacker to inject or manipulate the msg, title, and content parameters. This flaw can lead to reflected or stored cross site scripting, enabling malicious scripts to run in the context of affected users, potentially compromising session integrity or defacing content. The weakness is identified as CWE-79 and CWE-94.
Affected Systems
SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be performed remotely and public exploit code has been released. While the likelihood of exploitation cannot be precisely quantified without EPSS, the availability of an exploit suggests that the threat is non-negligible and warrants timely remediation.
OpenCVE Enrichment