CVE-2020-13278
PHP vulnerability analysis and mitigation

Overview

Reflected Cross-Site Scripting (XSS) vulnerability in Modules.php in RosarioSIS Student Information System versions prior to 6.5.1 was discovered in 2020. The vulnerability allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request (CVE Details, GitLab Issue).

Technical details

The vulnerability exists in the Modules.php component, specifically affecting the URL parameter handling. Attackers can exploit this by crafting special URLs containing malicious JavaScript or HTML tags in GET request parameters. A proof of concept demonstrates the vulnerability using a crafted URL: http://RosarioSIS.edu/Modules.php?modname=School_Setup/Rollover.php with injected script tags (GitLab Issue).

Impact

The successful exploitation of this vulnerability could lead to admin session hijacking or executing arbitrary requests using the administrator's session. The CVSS v3.1 scoring indicates Low confidentiality and integrity impact with no availability impact (C:L/I:L/A:N) (GitLab Issue).

Exploitability

The vulnerability can be exploited remotely and requires no authentication. The attack vector is rated as Network (AV:N) with Low attack complexity (AC:L) and requires user interaction (UI:R) according to the CVSS scoring (GitLab Issue).

Mitigation and workarounds

The vulnerability was fixed in RosarioSIS version 6.5.1 through URL encoding of key parameters. The fix was implemented in commit 9cb4fec5fe177f1d3716708b46d1958eac477ebe (GitLab Commit).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84361HIGH7.7
  • PHP logoPHP
  • composer
NoYesSep 01, 2026
GHSA-8rr7-cvq3-gmfhHIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 01, 2026
GHSA-jjv6-8j6v-6j52HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 01, 2026
GHSA-j8pm-gj4c-rq4xHIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 01, 2026
GHSA-f8fg-pg57-v4j8HIGH7.2
  • PHP logoPHP
  • league/commonmark
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management