S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 26, 2026

CVE-2020-15718 Scanner

CVE-2020-15718 Scanner - Cross-Site Scripting (XSS) vulnerability in RosarioSIS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
6.1
CVSS
Description

RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

RosarioSIS is primarily used by educational institutions for managing and organizing various academic activities. It serves as a comprehensive Student Information System (SIS) with functionalities such as grade management, attendance tracking, and student enrollment. The software is utilized by schools and colleges to streamline administrative tasks and improve communication among students, parents, and educators. With its modular architecture, RosarioSIS allows institutions to implement only the features they need, making it flexible and scalable. Additionally, it is an open-source solution, providing users with the ability to customize and adapt the system to their specific needs. Aside from core academic management, it also offers modules for discipline tracking, student billing, and scheduling.

The Cross-Site Scripting (XSS) vulnerability detected in RosarioSIS affects its Preferences module. This vulnerability arises when the 'tab' parameter in the Modules.php file is not properly sanitized. An attacker can exploit this flaw by crafting a malicious URL, which when accessed by a victim, can execute arbitrary JavaScript code in the victim's browser. Such vulnerabilities are commonly exploited to perform session hijacking, defacing web pages, or injecting malicious payloads. The XSS vulnerability poses a significant risk as it allows attackers to bypass the same-origin policy, which is a fundamental security constraint for modern web browsers. Thus, it is crucial to address this vulnerability promptly to ensure user safety.

The vulnerability is technically located in a specific parameter of a URL that interacts with the web application's Preferences module. By manipulating the 'tab' parameter in "Modules.php," attackers can inject JavaScript commands. This is primarily possible due to inadequate input validation processes in the application, which fail to detect and disallow potentially malicious scripts. The exploit can typically be activated by luring victims to click on a specially crafted link. When exploited, these malicious scripts execute in the browser of the person accessing the link, resulting in a breach of their session security. The payload primarily utilizes JavaScript events like 'onmouseover', allowing it to execute scripts surreptitiously when a user interacts with the page in a specific manner.

Exploiting this XSS vulnerability can lead to several adverse effects, most notably session hijacking. With this, an attacker can impersonate legitimate users and potentially access sensitive data, such as personal information or educational records. Credential theft is another potential consequence, as attackers can capture login credentials input by users while interacting with the compromised application. The execution of arbitrary JavaScript could also allow for deploying more sophisticated attacks, such as redirecting users to malicious websites or downloading harmful content onto users' devices. Furthermore, attackers might exploit the vulnerability to deface the application or disrupt its services, thereby affecting its reliability.

REFERENCES

Solution Advice
  • Update RosarioSIS to the latest version where input validation has been improved.
  • Implement robust input sanitization techniques across all modules, specifically targeting user-supplied data.
  • Regularly conduct security audits and code reviews to ensure adherence to secure coding standards.
  • Educate users on recognizing and avoiding phishing links that could exploit this vulnerability.
  • Configure Content Security Policy (CSP) headers to prevent the execution of unauthorized scripts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.