RosarioSIS
Products
2- 21 CVEs
- 1 CVE
Recent CVEs
21| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-44567 | Cri | 0.69 | 9.8 | 0.23 | Feb 24, 2022 | An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php. | ||
| CVE-2021-44427 | Cri | 0.61 | 9.8 | 0.51 | Nov 29, 2021 | An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter. | ||
| CVE-2022-2714 | Cri | 0.57 | 9.8 | 0.01 | Sep 6, 2022 | Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0. | ||
| CVE-2022-2067 | Cri | 0.52 | 9.1 | 0.02 | Jun 13, 2022 | SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0. | ||
| CVE-2025-29621 | Hig | 0.47 | 7.3 | 0.00 | Apr 22, 2025 | Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings. | ||
| CVE-2020-15718 | Med | 0.43 | 6.1 | 0.06 | Jul 15, 2020 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL. | ||
| CVE-2020-15716 | Med | 0.43 | 6.1 | 0.06 | Jul 15, 2020 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter in a crafted URL. | ||
| CVE-2023-2665 | Hig | 0.42 | 7.5 | 0.01 | May 12, 2023 | Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0. | ||
| CVE-2023-0994 | Hig | 0.42 | 7.5 | 0.01 | Feb 24, 2023 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2. | ||
| CVE-2021-45416 | Med | 0.40 | 6.1 | 0.02 | Feb 1, 2022 | Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script. | ||
| CVE-2020-13278 | Med | 0.40 | 6.1 | 0.01 | Aug 12, 2020 | Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request. | ||
| CVE-2020-15717 | Med | 0.40 | 6.1 | 0.02 | Jul 15, 2020 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL. | ||
| CVE-2020-15721 | Med | 0.40 | 6.1 | 0.01 | Jul 14, 2020 | RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php. | ||
| CVE-2026-93014 | Hig | 0.39 | 7.1 | 0.01 | Sep 17, 2026 | RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to escape upload directories and delete CSS,… | ||
| CVE-2023-29918 | Med | 0.38 | 5.4 | 0.02 | May 2, 2023 | RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module. | ||
| CVE-2023-2202 | Med | 0.35 | 6.5 | 0.01 | Apr 21, 2023 | Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3. | ||
| CVE-2021-44566 | Med | 0.35 | 5.4 | 0.01 | Feb 24, 2022 | A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 4.3 via the SanitizeMarkDown function in ProgramFunctions/MarkDownHTML.fnc.php. | ||
| CVE-2021-44565 | Med | 0.35 | 5.4 | 0.01 | Feb 24, 2022 | A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown input fields. | ||
| CVE-2022-3072 | Med | 0.28 | 5.4 | 0.01 | Sep 1, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 8.9.3. | ||
| CVE-2022-2036 | Med | 0.28 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1. |
- risk 0.69cvss 9.8epss 0.23
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
- risk 0.61cvss 9.8epss 0.51
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.
- risk 0.57cvss 9.8epss 0.01
Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0.
- risk 0.52cvss 9.1epss 0.02
SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.
- risk 0.47cvss 7.3epss 0.00
Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings.
- risk 0.43cvss 6.1epss 0.06
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.
- risk 0.43cvss 6.1epss 0.06
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter in a crafted URL.
- risk 0.42cvss 7.5epss 0.01
Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0.
- risk 0.42cvss 7.5epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.
- risk 0.40cvss 6.1epss 0.02
Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.
- risk 0.40cvss 6.1epss 0.01
Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request.
- risk 0.40cvss 6.1epss 0.02
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL.
- risk 0.40cvss 6.1epss 0.01
RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.
- risk 0.39cvss 7.1epss 0.01
RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to escape upload directories and delete CSS,…
- risk 0.38cvss 5.4epss 0.02
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
- risk 0.35cvss 6.5epss 0.01
Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3.
- risk 0.35cvss 5.4epss 0.01
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 4.3 via the SanitizeMarkDown function in ProgramFunctions/MarkDownHTML.fnc.php.
- risk 0.35cvss 5.4epss 0.01
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown input fields.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 8.9.3.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1.