A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/soursec/CVEs/tree/main/CVE-2024-45986 |
History
Thu, 26 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Online Voting System Project
Online Voting System Project online Voting System |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:online_voting_system_project:online_voting_system:1.0:*:*:*:*:*:*:* | |
Vendors & Products |
Online Voting System Project
Online Voting System Project online Voting System |
|
Metrics |
cvssV3_1
|
Thu, 26 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-26T00:00:00
Updated: 2024-09-26T20:48:18.055Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-45986
Vulnrichment
Updated: 2024-09-26T20:48:11.030Z
NVD
Status : Awaiting Analysis
Published: 2024-09-26T21:15:07.663
Modified: 2024-09-30T12:46:20.237
Link: CVE-2024-45986
Redhat
No data.