Online Birth Certificate System 1.2 contains multiple stored cross-site scripting vulnerabilities in the component /obcs/user/profile.php, which allows an attacker to execute arbitrary web script or HTML via a crafted payload injected into the fname or lname parameters.
View the template here CVE-2022-29005.yaml
References:
https://phpgurukul.com/online-birth-certificate-system-using-php-and-mysql/