Description
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown input fields.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0803 | A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown input fields. |
Github GHSA |
GHSA-44cg-qcpr-fwjh | Cross site scripting in francoisjacquet/rosariosis |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:25:16.818Z
Reserved: 2021-12-06T00:00:00.000Z
Link: CVE-2021-44565
No data.
Status : Modified
Published: 2022-02-24T15:15:24.107
Modified: 2024-11-21T06:31:13.487
Link: CVE-2021-44565
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA