CVE-2020-15721: XSS
Published Jul 14, 2020
·Updated
RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.
Affected Software
3 affected components
RosarioSIS RosarioSIS<=6.7.2
RosarioSIS RosarioSIS=6.8
RosarioSIS RosarioSIS=6.8-beta
Remediation
Event History
Jul 14, 2020
CVE Published
via MITRE·02:26 PM
Data Sourced
via MITRE·02:26 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15721?
CVE-2020-15721 is a vulnerability in RosarioSIS that allows XSS (Cross-Site Scripting) attacks.
2
What is the severity of CVE-2020-15721?
CVE-2020-15721 has a severity rating of 6.1 (medium).
3
How does CVE-2020-15721 affect RosarioSIS?
CVE-2020-15721 affects RosarioSIS versions 6.7.2, 6.8, and 6.8-beta.
4
How can I fix CVE-2020-15721?
To fix CVE-2020-15721 in RosarioSIS, apply the latest patches and updates provided by the vendor.
5
Where can I find more information about CVE-2020-15721?
More information about CVE-2020-15721 can be found in the references section.