
Proof-of-concept demonstrating stored XSS in RosarioSIS 8.2.1 with Docker setup and step-by-step payload execution for security testing.
Minimum requirements: Docker & Git working.
You can pull the image from DockerHub or:
$ git clone https://github.com/dnr6419/CVE-2021-45416.git
$ cd CVE-2021-45416
$ docker-compose up -d
http://YOURIP:80/InstallDatabase.php
Than, Go to the [http://YOURIP:80/InstallDatabase.php]
Default admin/password is "admin/admin"
Go to the Scheduling -> Student Schedule
Course Choose and click the search
Input the XSS payload
You can See the alert