Likely 0-day
RosarioSIS version 6.7.2 and earlier contains a reflected cross-site scripting (XSS) vulnerability in the Preferences module. The 'tab' parameter in Modules.php is not properly sanitized, allowing an attacker to inject arbitrary JavaScript code via a crafted URL.
id: rosariosis-xss
info:
name: RosarioSIS 6.7.2 - Cross-Site Scripting
author: 0xr2r,jarvis-sur
...