Vulnerabilities > Rosariosis > Rosariosis > 5.0.4

DATE CVE VULNERABILITY TITLE RISK
2023-05-12 CVE-2023-2665 Insecure Storage of Sensitive Information vulnerability in Rosariosis
Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0.
network
low complexity
rosariosis CWE-922
7.5
2023-04-21 CVE-2023-2202 Improper Access Control vulnerability in Rosariosis
Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3.
network
low complexity
rosariosis CWE-284
6.5
2023-02-24 CVE-2023-0994 Information Exposure vulnerability in Rosariosis
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.
network
low complexity
rosariosis CWE-200
7.5
2022-06-13 CVE-2022-2067 SQL Injection vulnerability in Rosariosis
SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.
network
low complexity
rosariosis CWE-89
6.4
2022-06-09 CVE-2022-2036 Cross-site Scripting vulnerability in Rosariosis
Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1.
network
rosariosis CWE-79
3.5
2022-06-08 CVE-2022-1997 Cross-site Scripting vulnerability in Rosariosis
Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.
network
rosariosis CWE-79
3.5
2022-02-24 CVE-2021-44565 Cross-site Scripting vulnerability in Rosariosis
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML.
network
rosariosis CWE-79
3.5
2022-02-24 CVE-2021-44567 SQL Injection vulnerability in Rosariosis
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
network
low complexity
rosariosis CWE-89
7.5
2021-11-29 CVE-2021-44427 SQL Injection vulnerability in Rosariosis
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.
network
low complexity
rosariosis CWE-89
7.5
2020-07-14 CVE-2020-15721 Cross-site Scripting vulnerability in Rosariosis
RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.
network
rosariosis CWE-79
4.3