VDB
Sign up
MEDIUM5.4

GHSA-f8hp-grmr-pp7j

RosarioSIS vulnerable to CSV Injection

Details

RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/francoisjacquet/rosariosis
Introduced in: 0

No fixed version published yet for francoisjacquet/rosariosis (composer). Pin to a known-safe version or switch to an alternative.

References