Skip to main content

Vendor archive

mindskip CVEs

Beta · best-effort

6 CVEs tagged to vendor mindskip1 Critical, 1 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2025-1084

Published Feb 7, 2025

A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this issue is some unknown functionality. The manipulation…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-1083

Published Feb 6, 2025

A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler…

CVSS 2.3 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-1082

Published Feb 6, 2025

A vulnerability classified as problematic has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected is an unknown function of the file /api/admin/question/edit of the compone…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-29401

Published Mar 26, 2024

xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-41431

Published Oct 17, 2022

xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. This vulnerability allows attackers to execute arbitrary web…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46086

Published Jan 25, 2022

xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1