
Cloud Vulnerability DB
A community-led vulnerabilities database
Reflected Cross-Site Scripting (XSS) vulnerability in Modules.php in RosarioSIS Student Information System versions prior to 6.5.1 was discovered in 2020. The vulnerability allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request (CVE Details, GitLab Issue).
The vulnerability exists in the Modules.php component, specifically affecting the URL parameter handling. Attackers can exploit this by crafting special URLs containing malicious JavaScript or HTML tags in GET request parameters. A proof of concept demonstrates the vulnerability using a crafted URL: http://RosarioSIS.edu/Modules.php?modname=School_Setup/Rollover.php with injected script tags (GitLab Issue).
The successful exploitation of this vulnerability could lead to admin session hijacking or executing arbitrary requests using the administrator's session. The CVSS v3.1 scoring indicates Low confidentiality and integrity impact with no availability impact (C:L/I:L/A:N) (GitLab Issue).
The vulnerability can be exploited remotely and requires no authentication. The attack vector is rated as Network (AV:N) with Low attack complexity (AC:L) and requires user interaction (UI:R) according to the CVSS scoring (GitLab Issue).
The vulnerability was fixed in RosarioSIS version 6.5.1 through URL encoding of key parameters. The fix was implemented in commit 9cb4fec5fe177f1d3716708b46d1958eac477ebe (GitLab Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."