A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 4.3 via the SanitizeMarkDown function in ProgramFunctions/MarkDownHTML.fnc.php.
References
Link | Resource |
---|---|
https://gitlab.com/francoisjacquet/rosariosis/-/blob/mobile/CHANGES_V3_4.md#changes-in-43 | Release Notes Third Party Advisory |
https://gitlab.com/francoisjacquet/rosariosis/-/commit/81886abb45a32e802151660de674f084afaef3aa | Patch Third Party Advisory |
https://gitlab.com/francoisjacquet/rosariosis/-/issues/259 | Exploit Issue Tracking Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-02-22T20:02:49
Updated: 2022-02-24T22:10:07
Reserved: 2021-12-06T00:00:00
Link: CVE-2021-44566
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-02-24T15:15:24.150
Modified: 2022-03-03T03:14:21.660
Link: CVE-2021-44566
JSON object: View
Redhat Information
No data.
CWE