www.vulncheck.com Path Traversal Vulnerability in RosarioSIS Allows File Deletion
Article Content
- •Path traversal vulnerability in RosarioSIS 12.8 allows file deletion.
- •Authenticated users can exploit this flaw to delete critical files.
- •Version 12.9 fixes the vulnerability; users must update immediately.
A path traversal vulnerability was discovered in RosarioSIS versions 12.8 and earlier, allowing authenticated users to delete files outside the intended directory. The vulnerability, identified as CWE-22, arises from improper handling of user-controlled filename parameters in file deletion handlers. Attackers could exploit this flaw to delete critical files, including user-uploaded documents and static resources. The issue was reported to the vendor, who has since released a fix in version 12.9. Public disclosure occurred after remediation, emphasizing the need for immediate updates. The vulnerability requires authentication, but could be exploited in conjunction with CSRF attacks if an administrator is tricked into submitting a request. The impact includes potential loss of data integrity and availability for affected systems. RosarioSIS users are advised to upgrade to version 12.9 to mitigate this risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…
Multiple CVEs Expose Vulnerabilities in Cybersecurity Tools and Applications A series of vulnerabilities have been reported affecting various cybersecurity tools and applications. Notable among them is CVE-2024-51482, a blind SQL injection vulnerability in ZoneMinder, allowing attackers to execute arbitrary SQL commands on the database server. CVE-2026-22557, a path traversal vulnerability in…