CVE-2020-15718 is a Cross-Site Scripting (XSS) vulnerability affecting RosarioSIS version 6.7.2, caused by improper input validation in the PrintSchedules.php script. This medium-severity flaw (CVSS 6.1) can be exploited remotely with low complexity, requiring user interaction to achieve low impacts on confidentiality and integrity. Public exploit code is available on ExploitDB (EDB-52449), and the vulnerability is listed on an active "Hot List." Its EPSS score indicates a higher likelihood of exploitation compared to most CVEs, and it has garnered significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.7.2CPE matchmatch criteria | cpe:2.3:a:rosariosis:rosariosis:6.7.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.