VulnerabilityModified
CVE-2020-29205
XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field
MEDIUM 6.1EPSS 1.53%
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- projectworlds/travel management system
- Source
- cve@mitre.org
References
- https://github.com/projectworldsofficial/online-examination-systen-in-phpThird Party Advisory
- https://nikhilkumar01.medium.com/cve-2020-29205-a7ab5cbcd156Third Party Advisory
- https://www.exploit-db.com/exploits/48969Exploit, Third Party Advisory, VDB Entry
- https://github.com/projectworldsofficial/online-examination-systen-in-phpThird Party Advisory
- https://nikhilkumar01.medium.com/cve-2020-29205-a7ab5cbcd156Third Party Advisory
- https://www.exploit-db.com/exploits/48969Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.