
Cloud Vulnerability DB
A community-led vulnerabilities database
RosarioSIS through version 6.8-beta contained a Cross-Site Scripting (XSS) vulnerability in modules/Custom/NotifyParents.php due to improper handling of href attributes in AddStudents.php and User.php. The vulnerability was discovered and disclosed on July 14, 2020 (NVD, MITRE).
The vulnerability exists due to insufficient sanitization of href attributes in AddStudents.php and User.php files within the NotifyParents.php module. The issue allows attackers to inject malicious scripts through these attributes. A fix was implemented by using URLEscape() function for links href attributes (GitLab Commit).
The XSS vulnerability could allow attackers to execute arbitrary web scripts or HTML code in the context of other users' browsers who access the affected pages. This could potentially lead to theft of sensitive information, session hijacking, or other client-side attacks (GitLab Issue).
The vulnerability can be exploited remotely by an attacker who can convince a user to access a specially crafted URL containing malicious JavaScript code in the href attributes. The attack requires user interaction to trigger the malicious script execution (GitLab Issue).
The vulnerability was fixed in the subsequent release after version 6.8-beta by implementing proper URL escaping for href attributes. Users should upgrade to the patched version to protect against this vulnerability (GitLab Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."