CVE-2020-15718: XSS
Published Jul 15, 2020
·Updated
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the includeinactive parameter in a crafted URL.
Affected Software
1 affected component
RosarioSIS RosarioSIS=6.7.2
Remediation
Event History
Jul 15, 2020
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
Description
Dec 3, 2025
Exploit Published
12:00 AM
Known Exploited
11:13 AM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-15718.
2
What is the severity of CVE-2020-15718?
The severity of CVE-2020-15718 is medium.
3
What is the affected software for CVE-2020-15718?
The affected software for CVE-2020-15718 is RosarioSIS version 6.7.2.
4
How does CVE-2020-15718 exploit the vulnerability?
CVE-2020-15718 exploits the vulnerability by using the include_inactive parameter in a crafted URL.
5
Are there any references available for CVE-2020-15718?
Yes, there are references available for CVE-2020-15718. You can find them at the following links: [link1], [link2], [link3].