/CVE-2021-45416

Stored XSS Vulnerability on RosarioSIS 8.2.1

Primary LanguagePHPMIT LicenseMIT

Docker RosarioSIS

Installation

Minimum requirements: Docker & Git working.

You can pull the image from DockerHub or:

  1. docker on
$ git clone https://github.com/dnr6419/CVE-2021-45416.git
$ cd CVE-2021-45416
$ docker-compose up -d
  1. Visit the URL and Install the Database
http://YOURIP:80/InstallDatabase.php
  1. Than, Go to the [http://YOURIP:80/InstallDatabase.php]

  2. Default admin/password is "admin/admin"

  3. Go to the Scheduling -> Student Schedule

  1. Course Choose and click the search

  1. Input the XSS payload

  1. You can See the alert

referernce

https://github.com/86x/CVE-2021-45416
https://github.com/francoisjacquet/docker-rosariosis