Vulnerability Description
Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can able to steal the cookie according to the crafted payload.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Janobe | Online Voting System | 1.0 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/49159Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/49159Third Party AdvisoryVDB Entry
FAQ
What is CVE-2020-29239?
CVE-2020-29239 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When a...
How severe is CVE-2020-29239?
CVE-2020-29239 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-29239?
Check the references section above for vendor advisories and patch information. Affected products include: Janobe Online Voting System.