An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
| Software | From | Fixed in |
|---|---|---|
| rosariosis / rosariosis | - | 7.6.1 |
francoisjacquet / rosariosis
|
- | 7.6.1 |