nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-29239 CVE-2020-29239
MEDIUM
Online Voting System Project in PHP - 'username' Persistent Cross-Site Scripting
Record summary
CVE-2020-29239 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can able to steal the cookie according to the crafted payload.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOnline Voting System Project in PHP - 'username' Persistent Cross-Site ScriptingExploitDB exploitby Sagar BanwaNot analyzed1 file
References
2exploit-db.com
https://www.exploit-db.com/exploits/49159