Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-15721 1 Rosariosis 1 Rosariosis 2024-11-21 6.1 Medium
RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.
CVE-2020-15717 1 Rosariosis 1 Rosariosis 2024-11-21 6.1 Medium
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL.