First published: Wed Dec 02 2020(Updated: )
Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can able to steal the cookie according to the crafted payload.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
janobe Online Voting System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-29239.
The severity level of CVE-2020-29239 is medium with a score of 6.1.
The affected software is the Online Birth Certificate System Project V 1.0.
CVE-2020-29239 allows an attacker to inject malicious scripts in the User Registration section, potentially leading to unauthorized access or data manipulation.
As a mitigation measure, it is recommended to apply the latest security patches or updates provided by the vendor of the Online Birth Certificate System Project.