VulnerabilityModified
CVE-2020-29239
Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS).
MEDIUM 6.1EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can able to steal the cookie according to the crafted payload.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- janobe/online voting system
- Source
- cve@mitre.org
References
- https://www.exploit-db.com/exploits/49159Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/49159Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.