ZeroHour

CVE-2024-45986

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p21
Published
()
Modified
Description

A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.

Vendors
projectworlds
Products
online voting system project
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.