CVE-2020-15717: XSS
Published Jul 15, 2020
·Updated
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL.
Affected Software
1 affected component
RosarioSIS RosarioSIS=6.7.2
Remediation
Event History
Jul 15, 2020
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15717?
CVE-2020-15717 is a vulnerability in RosarioSIS 6.7.2 that allows for XSS attacks.
2
How does CVE-2020-15717 work?
CVE-2020-15717 is caused by improper validation of user-supplied input by the Search.inc.php script, which allows a remote attacker to execute cross-site scripting (XSS) attacks.
3
What is the severity of CVE-2020-15717?
CVE-2020-15717 has a severity rating of 6.1, which is considered medium.
4
Which version of RosarioSIS is affected by CVE-2020-15717?
RosarioSIS version 6.7.2 is affected by CVE-2020-15717.
5
How can CVE-2020-15717 be fixed?
To fix CVE-2020-15717, you should update to a version of RosarioSIS that includes a patch for this vulnerability.