VYPR

xzs

by Mindskip

CVEs (3)

  • CVE-2026-75458HigAug 31, 2026
    risk 0.53cvss 8.1epss 0.00

    The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID and then executes getUserById(id), setDeleted(true), updateByIdFilter() in sequence,…

  • CVE-2026-75460MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.

  • CVE-2022-41431MedOct 17, 2022
    risk 0.35cvss 5.4epss 0.01

    xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.