{"api_version":"1","generated_at":"2026-07-23T11:00:42+00:00","cve":"CVE-2020-29205","urls":{"html":"https://cve.report/CVE-2020-29205","api":"https://cve.report/api/cve/CVE-2020-29205.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-29205","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-29205"},"summary":{"title":"CVE-2020-29205","description":"XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-05-17 19:15:00","updated_at":"2021-05-24 15:02:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://github.com/projectworldsofficial/online-examination-systen-in-php","name":"https://github.com/projectworldsofficial/online-examination-systen-in-php","refsource":"MISC","tags":[],"title":"GitHub - projectworldsofficial/online-examination-systen-in-php: Online Examination System Today Online Examination System has become a fast growing examination method because of its speed and accuracy. It is also needed less manpower to execute the examination. Almost all organizations now-a-days, are conducting their objective exams by online examination system, it saves students time in examinations. Organizations can also easily check the performance of the student that they give in an examination. As a","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/48969","name":"https://www.exploit-db.com/exploits/48969","refsource":"MISC","tags":[],"title":"Online Examination System 1.0 - 'name' Stored Cross Site Scripting - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://nikhilkumar01.medium.com/cve-2020-29205-a7ab5cbcd156","name":"https://nikhilkumar01.medium.com/cve-2020-29205-a7ab5cbcd156","refsource":"MISC","tags":[],"title":"CVE-2020–29205. #Exploit Title … | by Nikhil kumar | May, 2021 | Medium","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-29205","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-29205","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"29205","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"projectworlds","cpe5":"travel_management_system","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-29205","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/projectworldsofficial/online-examination-systen-in-php","refsource":"MISC","name":"https://github.com/projectworldsofficial/online-examination-systen-in-php"},{"url":"https://www.exploit-db.com/exploits/48969","refsource":"MISC","name":"https://www.exploit-db.com/exploits/48969"},{"refsource":"MISC","name":"https://nikhilkumar01.medium.com/cve-2020-29205-a7ab5cbcd156","url":"https://nikhilkumar01.medium.com/cve-2020-29205-a7ab5cbcd156"}]}},"nvd":{"publishedDate":"2021-05-17 19:15:00","lastModifiedDate":"2021-05-24 15:02:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:projectworlds:travel_management_system:1.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"29205","Ordinal":"192270","Title":"CVE-2020-29205","CVE":"CVE-2020-29205","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"29205","Ordinal":"1","NoteData":"XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field","Type":"Description","Title":null},{"CveYear":"2020","CveId":"29205","Ordinal":"2","NoteData":"2021-05-17","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"29205","Ordinal":"3","NoteData":"2021-05-24","Type":"Other","Title":"Modified"}]}}}