CVE-2025-28121

MEDIUM

Online Exam Mastering System 1.0 - Cross-Site Scripting via Feedback q Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-28121. PoCs published by Pruthu Raut, pruthuraut.

AI-analyzed exploit summary This is a working proof-of-concept for a reflected XSS vulnerability in code-projects Online Exam Mastering System 1.0, where the 'q' parameter in feedback.php is not properly sanitized, allowing arbitrary JavaScript execution.

Description

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.

Exploits (2)

exploitdb WORKING POC
by Pruthu Raut · textremotephp
https://www.exploit-db.com/exploits/52272

This is a working proof-of-concept for a reflected XSS vulnerability in code-projects Online Exam Mastering System 1.0, where the 'q' parameter in feedback.php is not properly sanitized, allowing arbitrary JavaScript execution.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: code-projects Online Exam Mastering System 1.0
No auth needed
Prerequisites: Access to the vulnerable feedback.php endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by pruthuraut · poc
https://github.com/pruthuraut/CVE-2025-28121

This repository contains a detailed writeup and proof-of-concept for CVE-2025-28121, a reflected XSS vulnerability in Online Exam Mastering System 1.0 via the `q` parameter in `feedback.php`. The PoC demonstrates how malicious JavaScript can be injected and executed in the victim's browser.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Online Exam Mastering System 1.0
No auth needed
Prerequisites: Access to the vulnerable endpoint · Victim interaction to trigger the payload
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0095
EPSS Percentile 76.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
code-projects/online_exam_mastering_system 1.0
Published Apr 21, 2025
Tracked Since Feb 18, 2026