CVE-2020-15721
on gitlab
Published
Severity
CVSS v3:
6.1 MEDIUM
CVSS v2:
4.3 MEDIUM
Description
RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.
References
Configurations
CPE23 | Version Start | Version End | Exact Version |
---|---|---|---|
cpe:2.3:a:rosariosis:rosariosis:*:*:*:*:*:*:*:* | n/a | 6.7.2 (including) | * |
cpe:2.3:a:rosariosis:rosariosis:6.8:-:*:*:*:*:*:* | n/a | n/a | 6.8 |
cpe:2.3:a:rosariosis:rosariosis:6.8:beta:*:*:*:*:*:* | n/a | n/a | 6.8 |