Impact
Affected code in the Student Medical Module (modules/Students/includes/Medical.inc.php) allows an unauthenticated attacker to inject arbitrary SQL by manipulating the argument table. This flaw, classified as CWE-74 and CWE-89, could enable the attacker to read, modify, or delete data in the underlying database, thereby compromising confidentiality, integrity, and potentially availability. The attack can be launched remotely when the vulnerable module is accessible.
Affected Systems
RosarioSIS versions up to 12.7.4 released by francoisjacquet contain the vulnerable code. Users running those releases (any deployment using the Student Medical Module) are affected. Upgrading to version 12.8 or applying the patch identified by commit 6234a0ee0124c0667c824693ac77164f18946ddf resolves the issue.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is considered moderate and requires remote interaction. EPSS information is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a known actively exploited flaw. Nonetheless, because the exploit requires only entry of crafted input into an accessible argument table, an attacker with network access to the web application could exploit it, leading to unauthorized database access.
OpenCVE Enrichment