Impact
RosarioSIS versions prior to 12.9 do not validate the filename request parameter in the Users and Students modules. This omission allows an authenticated user to supply a path‑traversal string in the filename parameter, causing the application to unlink files that are outside the intended upload directory. As a result, the attacker can delete CSS, XML, JSON resources and other users’ documents present anywhere within the installation.
Affected Systems
The vulnerability affects the RosarioSIS application from the RosarioSIS vendor. Any deployment running a version older than 12.9 is susceptible. The flaw exists regardless of the underlying operating system or web server; upgrading to 12.9 or later removes the issue.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as High severity, indicating significant potential for data loss. No EPSS score is reported, and the flaw is not listed in the CISA KEV catalog. The attack requires authentication; an internal or compromised user account can supply the malicious filename. If exploited, the attacker can delete critical files and documents, potentially impacting multiple users across the system.
OpenCVE Enrichment