Impact
The vulnerability resides in the admin/edit-user.php component of code-projects Assessment Management. By manipulating the parameters name, sname, email, username, password, and id, an attacker can inject arbitrary script code that is executed in the browser of users who view the affected page. This cross site scripting can lead to session hijacking, defacement, or the exfiltration of sensitive information. The compromise is limited to the browsers of impacted users and does not directly alter server data.
Affected Systems
Vendors: code-projects. Product: Assessment Management. Version: 1.0. The flaw is present in the user editing feature, specifically the file admin/edit-user.php, with no other versions documented in the advisory.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity vulnerability. The EPSS score is not available and the vulnerability is not listed in CISA KEV, so there is no current evidence of widespread exploitation. Because the attack can be initiated remotely by supplying crafted input to the edit-user functionality, the risk remains for authenticated administrators who process user edits. Without a publicly available patch, the primary remaining risk is the potential for attackers to deliver malicious scripts to any administrator browsing the affected interface.
OpenCVE Enrichment