Skip to content
Path Traversal Vulnerability in RosarioSIS Allows File Deletion

Path Traversal Vulnerability in RosarioSIS Allows File Deletion

First seen 18 Sep 2026, 01:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 02:00 UTC
  • Path traversal vulnerability in RosarioSIS 12.8 allows file deletion.
  • Authenticated users can exploit this flaw to delete critical files.
  • Version 12.9 fixes the vulnerability; users must update immediately.

A path traversal vulnerability was discovered in RosarioSIS versions 12.8 and earlier, allowing authenticated users to delete files outside the intended directory. The vulnerability, identified as CWE-22, arises from improper handling of user-controlled filename parameters in file deletion handlers. Attackers could exploit this flaw to delete critical files, including user-uploaded documents and static resources. The issue was reported to the vendor, who has since released a fix in version 12.9. Public disclosure occurred after remediation, emphasizing the need for immediate updates. The vulnerability requires authentication, but could be exploited in conjunction with CSRF attacks if an administrator is tricked into submitting a request. The impact includes potential loss of data integrity and availability for affected systems. RosarioSIS users are advised to upgrade to version 12.9 to mitigate this risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-18
Public disclosure of vulnerability
RosarioSIS vulnerability disclosed after vendor remediation, affecting versions 12.8 and earlier.
gist.github.com
2026-09-18
Security fix released
Vendor released RosarioSIS version 12.9 to address the path traversal vulnerability.
gist.github.com

More articles in this cluster (2)