PT-2026-94376 · Rosariosis+1 · Rosariosis

·

CVE-2026-93014

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions RosarioSIS versions prior to 12.9
Description Authenticated users can delete allow-listed files through a path traversal flaw in the Users and Students modules. By using parent-directory sequences in the filename request parameter, an attacker can escape upload directories to unlink CSS, XML, JSON resources, and documents belonging to other users across the installation. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations Update to version 12.9 or later. Restrict the use of the filename parameter in the Users and Students modules until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93014

Affected Products

Rosariosis