CVE-2020-15718

MEDIUM NUCLEI

RosarioSIS 6.7.2 - Cross-Site Scripting via PrintSchedules.php include_inactive Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-15718. PoCs published by CodeSecLab. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in RosarioSIS 6.7.2 via the 'include_inactive' parameter in the Scheduling module. The PoC uses an 'onmouseover' event to trigger an alert, confirming the vulnerability.

Description

RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.

Exploits (1)

exploitdb WORKING POC
by CodeSecLab · textwebappsphp
https://www.exploit-db.com/exploits/52449

This exploit demonstrates a reflected XSS vulnerability in RosarioSIS 6.7.2 via the 'include_inactive' parameter in the Scheduling module. The PoC uses an 'onmouseover' event to trigger an alert, confirming the vulnerability.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: RosarioSIS 6.7.2
Auth required
Prerequisites: Admin access to the RosarioSIS application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

RosarioSIS 6.7.2 - Cross-Site Scripting
MEDIUMVERIFIEDby 0xr2r,jarvis-survives
Shodan: http.html:"RosarioSIS"

Scores

CVSS v3 6.1
EPSS 0.1020
EPSS Percentile 93.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
rosariosis/rosariosis 6.7.2
Published Jul 15, 2020
Tracked Since Feb 18, 2026