CVE-2020-29239
MEDIUMOnline Birth Certificate System Project V 1.0 - XSS
Title source: llmDescription
Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can able to steal the cookie according to the crafted payload.
Exploits (1)
exploitdb
WORKING POC
by Sagar Banwa · textwebappsmultiple
https://www.exploit-db.com/exploits/49159
Scores
CVSS v3
6.1
EPSS
0.0011
EPSS Percentile
29.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
janobe/online_voting_system
1.0
Published
Dec 02, 2020
Tracked Since
Feb 18, 2026