Vulnerabilities (CVE)

Filtered by vendor Online Voting System Project Subscribe
Filtered by product Online Voting System
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-45987 1 Online Voting System Project 1 Online Voting System 2025-03-25 N/A 6.5 MEDIUM
Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious link that, when clicked by an authenticated user, automatically submits a vote for a specified party without the user's consent or knowledge. The attack leverages the user's active session to perform the unauthorized action, compromising the integrity of the voting process.
CVE-2020-29239 1 Online Voting System Project 1 Online Voting System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can able to steal the cookie according to the crafted payload.