CVE-2020-15716: XSS
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter in a crafted URL.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-15716?
CVE-2020-15716 is a vulnerability in RosarioSIS 6.7.2 that allows for cross-site scripting (XSS) attacks.
How does CVE-2020-15716 occur?
CVE-2020-15716 occurs due to improper validation of user-supplied input by the Preferences.php script in RosarioSIS 6.7.2.
What is the severity of CVE-2020-15716?
The severity of CVE-2020-15716 is medium with a CVSS score of 6.1.
How can CVE-2020-15716 be exploited?
CVE-2020-15716 can be exploited by a remote attacker using the tab parameter in a crafted URL.
Is there a fix available for CVE-2020-15716?
Yes, a fix for CVE-2020-15716 is available in the latest version of RosarioSIS. It is recommended to update to the latest version to mitigate this vulnerability.