CVE-2025-1084 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Mindskip xzs-mysql 学之思开源考试系统 version 3.9.0. This issue allows an unauthenticated, remote attacker to perform unwanted actions on behalf of an authenticated user, with a low impact on integrity and no impact on confidentiality or availability. Although the exploit has been publicly disclosed, there is currently no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.9.0CPE matchmatch criteria | cpe:2.3:a:mindskip:xzs-mysql:3.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.