A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00065}

epss

{'score': 0.00071}


Tue, 06 May 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Projectworlds
Projectworlds online Voting System Project
CPEs cpe:2.3:a:projectworlds:online_voting_system_project:1.0:*:*:*:*:*:*:*
Vendors & Products Projectworlds
Projectworlds online Voting System Project

Thu, 26 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Online Voting System Project
Online Voting System Project online Voting System
Weaknesses CWE-79
CPEs cpe:2.3:a:online_voting_system_project:online_voting_system:1.0:*:*:*:*:*:*:*
Vendors & Products Online Voting System Project
Online Voting System Project online Voting System
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Description A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-26T20:48:18.055Z

Reserved: 2024-09-11T00:00:00

Link: CVE-2024-45986

cve-icon Vulnrichment

Updated: 2024-09-26T20:48:11.030Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-26T21:15:07.663

Modified: 2025-05-06T21:16:36.850

Link: CVE-2024-45986

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.