CVE-2025-1083 is a problematic cross-origin resource sharing (CORS) vulnerability affecting Mindskip xzs-mysql 学之思开源考试系统 version 3.9.0. This flaw allows for a permissive cross-domain policy with untrusted domains, potentially enabling unauthorized access to resources. Rated with a CVSS score of 6.8 (Medium), the attack is remote but has high complexity and difficult exploitation, requiring user interaction. If successful, it could lead to high impact on confidentiality and integrity. While the exploit has been publicly disclosed, there is no evidence of active exploitation, Metasploit modules, or Nuclei templates. Community discussion and media coverage are minimal, and the vendor has not responded to disclosure attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.9.0CPE matchmatch criteria | cpe:2.3:a:mindskip:xzs-mysql:3.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.