Impact
A cross‑site scripting flaw exists in the admin/add-user.php script of code‑projects Assessment Management 1.0. The flaw is triggered by manipulating the "level" request argument, allowing an attacker to inject arbitrary script code into the page response. The vulnerability can be exploited over the network and the exploit code has already been released publicly, implying that remote attackers can use it immediately after discovering the target.
Affected Systems
The affected product is code‑projects Assessment Management, current stable release 1.0. No other versions or build variants are specified in the CVE record. Systems running this version without any patch or mitigation are vulnerable.
Risk and Exploitability
The CVSS score of 4.8 points to a moderate impact. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the fact that the vulnerability is publicly known and remotely exploitable increases the practical risk. The CVE is not listed in the CISA KEV catalog, suggesting it has not yet been widely observed in the wild. Attackers can send crafted requests to the level parameter from any network location, resulting in XSS injection that may allow session hijacking, defacement, or delivery of malicious content to logged‑in administrators.
OpenCVE Enrichment