PT-2020-14608 · Rosariosis · Rosariosis
M507
·
Published
2020-07-14
·
Updated
2022-02-10
·
CVE-2020-15721
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
RosarioSIS versions prior to 6.8-beta
Description
The issue is related to a problem with the href attributes for "AddStudents.php" and "User.php" in the NotifyParents.php file within the Custom module, allowing for XSS attacks.
Recommendations
For RosarioSIS versions prior to 6.8-beta, as a temporary workaround, consider restricting access to the NotifyParents.php file in the Custom module until a patch is available. Avoid using the href attributes for "AddStudents.php" and "User.php" in the NotifyParents.php file until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rosariosis