RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15721
Reference (s):
- https://gitlab.com/francoisjacquet/rosariosis/-/blob/mobile/CHANGES.md
- https://gitlab.com/francoisjacquet/rosariosis/-/commit/c4a694860b50c4aa5c67d6568f7d0613fef1a30d
- https://gitlab.com/francoisjacquet/rosariosis/-/issues/291

