PT-2026-94376 · Rosariosis+1 · Rosariosis
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
RosarioSIS versions prior to 12.9
Description
Authenticated users can delete allow-listed files through a path traversal flaw in the Users and Students modules. By using parent-directory sequences in the
filename request parameter, an attacker can escape upload directories to unlink CSS, XML, JSON resources, and documents belonging to other users across the installation. Path traversal is a technique used to access files and directories that are stored outside the web root folder.Recommendations
Update to version 12.9 or later.
Restrict the use of the
filename parameter in the Users and Students modules until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rosariosis