{ "schema_version": "1.4.0", "id": "GHSA-vh4m-mw8w-g4w8", "modified": "2022-09-15T03:20:14Z", "published": "2022-09-07T00:01:54Z", "aliases": [ "CVE-2022-2714" ], "summary": "RosarioSIS before 10.1 vulnerable to Improper Handling of Length Parameter Inconsistency", "details": "RosarioSIS Student Information System prior to version 10.1 is vulnerable to Improper Handling of Length Parameter Inconsistency.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], "affected": [ { "package": { "ecosystem": "Packagist", "name": "francoisjacquet/rosariosis" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "10.1" } ] } ] } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2714" }, { "type": "WEB", "url": "https://github.com/francoisjacquet/rosariosis/commit/4022954c3f41462bf6225c302a28b0429f6f4df3" }, { "type": "PACKAGE", "url": "https://github.com/francoisjacquet/rosariosis" }, { "type": "WEB", "url": "https://huntr.dev/bounties/430aedac-c7d9-4acb-9bab-bcc0595d9e95" } ], "database_specific": { "cwe_ids": [ "CWE-130" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-09-15T03:20:14Z", "nvd_published_at": "2022-09-06T11:15:00Z" } }