RosarioSIS version 6.7.2 and earlier contains a reflected cross-site scripting (XSS) vulnerability in the Preferences module. The 'tab' parameter in Modules.php is not properly sanitized, allowing an attacker to inject arbitrary JavaScript code via a crafted URL.
id: CVE-2020-15718
info:
name: RosarioSIS 6.7.2 - Cross-Site Scripting
author: 0xr2r,jarvis-sur
...