Record summary

CVE-2020-29239 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.

Description

Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can able to steal the cookie according to the crafted payload.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBOnline Voting System Project in PHP - 'username' Persistent Cross-Site ScriptingExploitDB exploitby Sagar BanwaNot analyzed1 file
ExploitDB

PoC details

References

2