PT-2026-92111 · Unknown · Design Scuole Italia

·

CVE-2026-87792

·

Published

2026-09-15

·

Updated

2026-09-24

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Design Scuole Italia (affected versions not specified)
Description Authorization bypass issues exist within the dsi pdf generator() and dsi csv generator() functions. These flaws allow an unauthenticated attacker to access restricted "Circolare" content and sensitive data belonging to registered users. The exploitation process is further facilitated by an unauthenticated RSS feed located at the '/circolare/feed/' endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87792

Affected Products

Design Scuole Italia