Medium severity6.1NVD Advisory· Published Jul 15, 2020· Updated Jun 17, 2026
CVE-2020-15717
CVE-2020-15717
Description
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:rosariosis:rosariosis:6.7.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rosariosis:rosariosis:6.7.2:*:*:*:*:*:*:*
- (no CPE)range: <6.7.2
- RosarioSIS/RosarioSISdescription
Patches
Vulnerability mechanics
References
5- gitlab.com/francoisjacquet/rosariosis/-/commit/89ae9de732024e3a2e99262aa98b400a1aa6975anvdPatchThird Party Advisory
- gitlab.com/francoisjacquet/rosariosis/-/blob/mobile/CHANGES.mdnvdRelease NotesThird Party Advisory
- gitlab.com/francoisjacquet/rosariosis/-/tags/v6.8-betanvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/184943nvdVDB Entry
- gitlab.com/francoisjacquet/rosariosis/-/issues/291nvdBroken Link
News mentions
0No linked articles in our index yet.