PT-2020-17116 · Unknown · Online Birth Certificate System Project
Published
2020-12-02
·
Updated
2023-10-03
·
CVE-2020-29239
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Online Birth Certificate System Project version 1.0
Description
The issue is related to cross-site scripting (XSS), which allows an attacker to inject a malicious payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can steal the cookie according to the crafted payload. This occurs because the application does not properly validate user input, enabling the attacker to execute arbitrary code.
Recommendations
As a temporary workaround, consider disabling the User Registration section until a patch is available. Restrict access to the View Detail of Application section from the admin panel to minimize the risk of exploitation. Avoid using the User Registration section until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Online Birth Certificate System Project