CVE-2025-1083 | Mindskip xzs-mysql 学之思开源考试系统 3.9.0 CORS cross-domain policy
A vulnerability was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0 and classified as problematic. This vulnerability affects unknown code of the component CORS Handler. The manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability was named CVE-2025-1083. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.