Impact
A logic flaw in the DBUpdate function of RosarioSIS's Discipline/Referrals.php allows an attacker to bypass authorization controls. The flaw enables manipulation of referral data by unsafely trusting input parameters, permitting unauthorized modification of records. The vulnerability is classified under CWE-285 and CWE-639, indicating improper authorization handling and potential privilege dropping.
Affected Systems
RosarioSIS developed by francoisjacquet, versions up through 12.8 inclusive, are affected. The issue originates from the Discipline/Referrals.php module. Upgrading to version 12.9 or later resolves the authorization bypass.
Risk and Exploitability
The CVSS score of 5.3 denotes a moderate risk, and the EPSS score is not available, suggesting no current evidence of widespread exploitation. The vulnerability can be triggered remotely through the application's web interface, and exploit code has already been published. Although the vulnerability is not listed in CISA's KEV catalog, it remains a legitimate threat and should be addressed promptly.
OpenCVE Enrichment