RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to escape upload directories and delete CSS, XML, JSON resources and other users' documents throughout the installation.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to escape upload directories and delete CSS, XML, JSON resources and other users' documents throughout the installation. | |
| Title | RosarioSIS before 12.9 Path Traversal in File Deletion via filename Parameter | |
| First Time appeared |
Rosariosis
Rosariosis rosariosis |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:rosariosis:rosariosis:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rosariosis
Rosariosis rosariosis |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T15:47:11.421Z
Reserved: 2026-09-17T14:45:57.907Z
Link: CVE-2026-93014
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses