Bounties
Partners
Community
Info
francoisjacquet / rosariosis
Project repository
RosarioSIS Student Information System for school management.
Submit a report
FIRST INTERACTION
WITHIN
N/A DAYS
REVIEW
WITHIN
16 DAYS
FIX
WITHIN
17 DAYS
Server-Side Request Forgery (SSRF) Vulnerability Enabling Proxy Behavior
May 31st 2023
jsnv-dev
•
pending
RosarioSIS Server-Side Request Forgery (SSRF)
May 29th 2023
jsnv-dev
•
informative
Critical
RosarioSIS Cross-Site Request Forgery (CSRF)
Jul 27th 2023
jsnv-dev
•
self closed
Attached files under salaries module can be harvested by unauthenticated users
May 12th 2023
b1tch3s
•
High
High
•
CVE-2023-2665
CVE-2023-2665
Browser back attack vulnerability
Apr 21st 2023
b1tch3s
•
Medium
Medium
•
CVE-2023-2202
CVE-2023-2202
Parameter Pollution in `reason` parameter
Mar 5th 2023
test13372
•
pending
Broken Access Control
Feb 24th 2023
jeffreygaor
•
High
High
•
CVE-2023-0994
CVE-2023-0994
Arbitrary File Upload Lead to Cross-Site Scripting Stored
Feb 17th 2023
jeffreygaor
•
not applicable
Improper Exception Handling of Integer Input Validation Discloses MySQL DB Attri...
Aug 4th 2022
ahmad0x1
•
duplicate
High
No Rate Limit when creating Objects (ex: Assignments)
Aug 4th 2022
ahmad0x1
•
informative
High
Bypass filter - Stored XSS in Resources
Jun 8th 2022
domiee13
•
Critical
•
$10
Critical
•
$10
•
CVE-2022-2036
CVE-2022-2036
Bypass filter - Stored XSS in Resources
Jun 5th 2022
domiee13
•
duplicate
High
Bypass filter - Stored XSS in Resources
Jun 4th 2022
domiee13
•
High
•
$5
High
•
$5
•
CVE-2022-1997
CVE-2022-1997
Stored XSS in Resources
Jun 3rd 2022
domiee13
•
High
•
$5
High
•
$5
HTML Injection stored on Portal Notes
May 30th 2022
nilabhrajpoot
•
self closed
Student price field accepts negative price
May 25th 2022
domiee13
•
informative
Low
Cross-site Scripting (XSS) - Stored
May 25th 2022
appsectr
•
Critical
•
$10
Critical
•
$10
Improper Restriction of Excessive Authentication Attempts in login feature
May 24th 2022
domiee13
•
Medium
Medium
XSS Stored in SIde.php file
May 23rd 2022
kira2040k
•
self closed
Cross-site Scripting (XSS) - Reflected
May 22nd 2022
dungtuanha
•
Critical
•
$7.5
Critical
•
$7.5
Cross-site Scripting (XSS) - Reflected
May 10th 2022
dungtuanha
•
Critical
•
$10
Critical
•
$10
Cross site scripting
May 7th 2022
gaurav-g2
•
Critical
•
$9
Critical
•
$9
Improper File Deletion in francoisjacquet/rosariosis
May 8th 2022
gaurav-g2
•
not applicable
iframe injection
May 5th 2022
tharunavula
•
not applicable
Improper Access Control
May 3rd 2022
khanhchauminh
•
pending
Improper Access Control
May 4th 2022
appsectr
•
Critical
•
$12
Critical
•
$12
Cross-site Scripting (XSS) - Stored
May 4th 2022
appsectr
•
Critical
•
$10
Critical
•
$10
Improper File Deletion
May 4th 2022
khanhchauminh
•
Critical
•
$16
Critical
•
$16
Improper handling of large integer values
May 4th 2022
nhienit2010
•
High
•
$5
High
•
$5
Improper handling of error messages leads to exposure of sensitive information
Jul 3rd 2022
nhienit2010
•
self closed
Cross-site scripting via upload `.md` file
May 2nd 2022
nhienit2010
•
self closed
Improper file deletion
May 1st 2022
gaurav-g2
•
Critical
•
$10
Critical
•
$10
SQL injection
May 5th 2022
khanhchauminh
•
not applicable
Cross-site Scripting (XSS) - Stored
May 1st 2022
khanhchauminh
•
Critical
•
$10
Critical
•
$10
Exposure of Sensitive Information to an Unauthorized Actor
Apr 30th 2022
dungtuanha
•
Critical
•
$10
Critical
•
$10
Improper Access Control (IDOR)
Apr 30th 2022
dungtuanha
•
Critical
•
$10
Critical
•
$10
Cross-site Scripting (XSS) - Stored
Apr 29th 2022
appsectr
•
High
•
$5
High
•
$5
SQL injection at remove function in PortalNote.php
Apr 30th 2022
nhienit2010
•
self closed
Cross-site Request Forgery (CSRF) in remove function
Apr 30th 2022
nhienit2010
•
self closed
Cross-site Scripting (XSS) - Stored via htm file upload
Apr 28th 2022
khanhchauminh
•
Critical
•
$10
Critical
•
$10
Cross-site Scripting (XSS) - Stored via xHTML file upload
Apr 28th 2022
khanhchauminh
•
Critical
•
$10
Critical
•
$10
Small Space of Random Values
Apr 27th 2022
appsectr
•
Critical
•
$10
Critical
•
$10
Cross-site Scripting (XSS) - Stored via HTML file upload
Apr 27th 2022
khanhchauminh
•
Critical
•
$10
Critical
•
$10
SQL injection in Calendar.php
Apr 26th 2022
minhnb11
•
High
•
$5
High
•
$5
•
CVE-2022-2067
CVE-2022-2067
Cross-site Scripting (XSS) - Stored
Apr 26th 2022
appsectr
•
High
•
$5
High
•
$5
Cross-site Scripting (XSS) - Stored
Apr 25th 2022
dungtuanha
•
Critical
•
$10
Critical
•
$10
Cross-site scripting - Stored via upload xml file
Apr 26th 2022
nhienit2010
•
Critical
•
$10
Critical
•
$10
SQL injection in PortalNotes
Apr 23rd 2022
nhienit2010
•
Critical
•
$10
Critical
•
$10
Cross-site scripting - Reflected via mime-type file upload
Apr 23rd 2022
nhienit2010
•
Critical
•
$10
Critical
•
$10
Cross-site Scripting (XSS) - Stored
Apr 23rd 2022
dungtuanha
•
duplicate
Critical
Insufficient Session Expiration
Apr 16th 2022
crowdoverflow
•
pending
Stored XSS viva .svg file upload
Apr 21st 2022
crowdoverflow
•
duplicate
Critical
Cross-Site Request Forgery (CSRF)
Apr 25th 2022
khanhchauminh
•
Medium
•
$7.5
Medium
•
$7.5
SQL Injection
Apr 30th 2022
scgajge12
•
not applicable
Cross-site Scripting (XSS) - Stored
Apr 21st 2022
scgajge12
•
High
•
$7.5
High
•
$7.5
•
CVE-2022-3072
CVE-2022-3072
Improper Restriction of Rendered UI Layers or Frames
Apr 20th 2022
sudheendra17
•
Medium
Medium
Cross-Site Request Forgery (CSRF)
Aug 2nd 2021
am0o0
•
High
•
$25
High
•
$25
Cross-Site Request Forgery (CSRF)
Aug 2nd 2021
am0o0
•
High
•
$25
High
•
$25
Cross-Site Request Forgery (CSRF)
Aug 2nd 2021
am0o0
•
Medium
•
$25
Medium
•
$25
Cross-Site Request Forgery (CSRF)
Aug 2nd 2021
am0o0
•
Medium
•
$25
Medium
•
$25
Cross-Site Request Forgery (CSRF)
Aug 2nd 2021
am0o0
•
High
•
$25
High
•
$25
Cross-Site Request Forgery (CSRF)
Aug 2nd 2021
am0o0
•
Medium
•
$25
Medium
•
$25
Cross-Site Request Forgery (CSRF)
Aug 2nd 2021
am0o0
•
Medium
•
$25
Medium
•
$25
Cross-Site Request Forgery (CSRF)
Aug 2nd 2021
am0o0
•
High
•
$25
High
•
$25
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0