CVE-2021-45416: XSS
Published Feb 1, 2022
·Updated
Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the searchterm parameter in the modules/Scheduling/Courses.php script.
Affected Software
1 affected component
RosarioSIS RosarioSIS=8.2.1
Remediation
Patch Available
Event History
Feb 1, 2022
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
Description
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-45416.
2
What is the title of the vulnerability?
The title of the vulnerability is Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.
3
What is the affected software?
The affected software is RosarioSIS version 8.2.1.
4
What is the severity of CVE-2021-45416?
The severity of CVE-2021-45416 is medium with a CVSS score of 6.1.
5
How can I fix CVE-2021-45416?
To fix CVE-2021-45416, it is recommended to update RosarioSIS to a version that addresses the vulnerability.