VYPR
Medium severity6.1NVD Advisory· Published Jul 14, 2020· Updated Jun 17, 2026

CVE-2020-15721

CVE-2020-15721

Description

RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
francoisjacquet/rosariosisPackagist
< 6.86.8

Affected products

5
  • cpe:2.3:a:rosariosis:rosariosis:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:rosariosis:rosariosis:*:*:*:*:*:*:*:*range: <=6.7.2
    • cpe:2.3:a:rosariosis:rosariosis:6.8:-:*:*:*:*:*:*
    • cpe:2.3:a:rosariosis:rosariosis:6.8:beta:*:*:*:*:*:*
  • RosarioSIS/RosarioSISdescription

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.