CVE-2020-15718
MEDIUM NUCLEIRosarioSIS 6.7.2 - Cross-Site Scripting via PrintSchedules.php include_inactive Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-15718. PoCs published by CodeSecLab. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in RosarioSIS 6.7.2 via the 'include_inactive' parameter in the Scheduling module. The PoC uses an 'onmouseover' event to trigger an alert, confirming the vulnerability.
Description
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in RosarioSIS 6.7.2 via the 'include_inactive' parameter in the Scheduling module. The PoC uses an 'onmouseover' event to trigger an alert, confirming the vulnerability.
Nuclei Templates (1)
http.html:"RosarioSIS"
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N