CVE-2022-29005
https://notcve.org/view.php?id=CVE-2022-29005
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters. Múltiples vulnerabilidades de tipo cross-site scripting (XSS) en el componente /obcs/user/profile.php de Online Birth Certificate System versión v1.2, permite a atacantes ejecutar scripts web o HTML arbitrarios por medio de una carga útil diseñada inyectada en los parámetros fname o lname • https://github.com/sudoninja-noob/CVE-2022-29005 http://online.com https://github.com/sudoninja-noob/CVE-2022-29005/blob/main/CVE-2022-29005.txt https://phpgurukul.com/online-birth-certificate-system-using-php-and-mysql • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •