RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://gitlab.com/francoisjacquet/rosariosis/-/blob/mobile/CHANGES.md | third party advisory release notes |
https://gitlab.com/francoisjacquet/rosariosis/-/issues/291 | broken link |
https://gitlab.com/francoisjacquet/rosariosis/-/commit/c4a694860b50c4aa5c67d6568f7d0613fef1a30d | third party advisory patch |