HIGH 7.1 NVD
CVE-2026-93014
RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-list
RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to escape upload directories and delete CSS, XML, JSON resources and other users' documents throughout the installation.
References
- https://gist.github.com/kazisabu/68bd095bc05b2341db318a063e05e644
- https://gitlab.com/francoisjacquet/rosariosis
- https://gitlab.com/francoisjacquet/rosariosis/-/commit/701f9c07330157181362927a40d4f8dcc80
- https://www.vulncheck.com/advisories/rosariosis-before-12.9-path-traversal-in-file-deletio
- https://gist.github.com/kazisabu/68bd095bc05b2341db318a063e05e644
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-17 via NVD.
vulnfeed aggregates 12865 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.