A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/soursec/CVEs/tree/main/CVE-2024-45986 |
|
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 06 May 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Projectworlds
Projectworlds online Voting System Project |
|
| CPEs | cpe:2.3:a:projectworlds:online_voting_system_project:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Projectworlds
Projectworlds online Voting System Project |
Thu, 26 Sep 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Online Voting System Project
Online Voting System Project online Voting System |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:online_voting_system_project:online_voting_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Online Voting System Project
Online Voting System Project online Voting System |
|
| Metrics |
cvssV3_1
|
Thu, 26 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-26T00:00:00
Updated: 2024-09-26T20:48:18.055Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-45986
Updated: 2024-09-26T20:48:11.030Z
Status : Analyzed
Published: 2024-09-26T21:15:07.663
Modified: 2025-05-06T21:16:36.850
Link: CVE-2024-45986
No data.