Description
RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to escape upload directories and delete CSS, XML, JSON resources and other users' documents throughout the installation.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: File Deletion via Path Traversal
Action: Patch
AI Analysis

Impact

RosarioSIS versions prior to 12.9 do not validate the filename request parameter in the Users and Students modules. This omission allows an authenticated user to supply a path‑traversal string in the filename parameter, causing the application to unlink files that are outside the intended upload directory. As a result, the attacker can delete CSS, XML, JSON resources and other users’ documents present anywhere within the installation.

Affected Systems

The vulnerability affects the RosarioSIS application from the RosarioSIS vendor. Any deployment running a version older than 12.9 is susceptible. The flaw exists regardless of the underlying operating system or web server; upgrading to 12.9 or later removes the issue.

Risk and Exploitability

The CVSS score of 7.1 classifies the issue as High severity, indicating significant potential for data loss. No EPSS score is reported, and the flaw is not listed in the CISA KEV catalog. The attack requires authentication; an internal or compromised user account can supply the malicious filename. If exploited, the attacker can delete critical files and documents, potentially impacting multiple users across the system.

Generated by OpenCVE AI on September 17, 2026 at 22:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest RosarioSIS 12.9 release or any later version to remove the path‑traversal flaw.
  • If an upgrade cannot be performed immediately, implement the code patch at https://gitlab.com/francoisjacquet/rosariosis/-/commit/701f9c07330157181362927a40d4f8dcc8094d90 to validate filenames and block directory traversal.
  • Restrict file‑deletion permissions to a minimal set of trusted administrators to reduce exposure.

Generated by OpenCVE AI on September 17, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to escape upload directories and delete CSS, XML, JSON resources and other users' documents throughout the installation.
Title RosarioSIS before 12.9 Path Traversal in File Deletion via filename Parameter
First Time appeared Rosariosis
Rosariosis rosariosis
Weaknesses CWE-22
CPEs cpe:2.3:a:rosariosis:rosariosis:*:*:*:*:*:*:*:*
Vendors & Products Rosariosis
Rosariosis rosariosis
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Rosariosis Rosariosis
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:47:11.421Z

Reserved: 2026-09-17T14:45:57.907Z

Link: CVE-2026-93014

cve-icon Vulnrichment

Updated: 2026-09-17T15:47:00.561Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T16:18:35.670

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-93014

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:15:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')