Vulnerabilities > Fauzantrif Election Project

DATE CVE VULNERABILITY TITLE RISK
2020-02-22 CVE-2020-9340 SQL Injection vulnerability in Fauzantrif Election Project Fauzantrif Election 2.0
fauzantrif eLection 2.0 has SQL Injection via the admin/ajax/op_kandidat.php id parameter.
network
low complexity
fauzantrif-election-project CWE-89
7.2
2020-02-22 CVE-2020-9336 Cross-site Scripting vulnerability in Fauzantrif Election Project Fauzantrif Election 2.0
fauzantrif eLection 2.0 has XSS via the Admin Dashboard -> Settings -> Election -> "message if election is closed" field.
network
low complexity
fauzantrif-election-project CWE-79
5.4