Impact
A flaw in the handling of the Modules.php file in RosarioSIS allows an attacker to trigger cross‑site request forgery. By crafting a malicious request that is sent while a legitimate user is authenticated, the attacker can cause the application to perform state‑changing actions on behalf of that user. This remote exploitation permits manipulation of data or administrative actions without direct access to the victim’s session.
Affected Systems
The affected vendor is francoisjacquet and the product is RosarioSIS. All releases up to and including version 12.8 are vulnerable due to the Modules.php implementation. Version 12.9, released by the vendor, includes the patch that removes the CSRF vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. EPSS is not available, so the current likelihood of exploitation remains uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. The attack is performed via a remote web request hosted by a malicious site; it relies on an exposed web interface and the victim’s existing authenticated session.
OpenCVE Enrichment