RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://gitlab.com/francoisjacquet/rosariosis/-/blob/mobile/CHANGES.md | third party advisory release notes |
https://gitlab.com/francoisjacquet/rosariosis/-/issues/291 | broken link |
https://gitlab.com/francoisjacquet/rosariosis/-/tags/v6.8-beta | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/184943 | vdb entry |
https://gitlab.com/francoisjacquet/rosariosis/-/commit/89ae9de732024e3a2e99262aa98b400a1aa6975a | third party advisory patch |