CVE-2025-1082 | Mindskip xzs-mysql 学之思开源考试系统 3.9.0 Exam Edit /api/admin/question/edit title/content cross site scripting
A vulnerability has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0 and classified as problematic. This affects an unknown part of the file /api/admin/question/edit of the component Exam Edit Handler. The manipulation of the argument title/content leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-1082. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.