Impact
A cross‑site scripting flaw exists in the add-single-mark.php endpoint of code‑projects Assessment Management, triggered by manipulating the mark argument. This flaw allows arbitrary client‑side script to be injected and executed in the victim’s browser context. Based on the description, it is inferred that an attacker could potentially deface pages or hijack sessions, but these specific consequences are not detailed in the statement.
Affected Systems
The affected product is code‑projects Assessment Management 1.0. No other versions or sub‑products are referenced, and no further version qualifiers are available. Applications that host or interact with this component are at risk if the same file path and input parameter exist.
Risk and Exploitability
The CVSS base score of 5.1 indicates medium severity. EPSS data is not available and the vulnerability is not listed in KEV. Public exploits are known and the attack can be launched remotely. The overall risk is uncertain; while the impact could be significant if the injected script runs, precise exploitation likelihood cannot be quantified without EPSS.
OpenCVE Enrichment