PT-2020-17116 · Unknown · Online Birth Certificate System Project

Published

2020-12-02

·

Updated

2023-10-03

·

CVE-2020-29239

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Online Birth Certificate System Project version 1.0
Description The issue is related to cross-site scripting (XSS), which allows an attacker to inject a malicious payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can steal the cookie according to the crafted payload. This occurs because the application does not properly validate user input, enabling the attacker to execute arbitrary code.
Recommendations As a temporary workaround, consider disabling the User Registration section until a patch is available. Restrict access to the View Detail of Application section from the admin panel to minimize the risk of exploitation. Avoid using the User Registration section until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-29239

Affected Products

Online Birth Certificate System Project