CVE-2026-93014 Details
Description
RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to escape upload directories and delete CSS, XML, JSON resources and other users' documents throughout the installation.
A path traversal vulnerability has been identified in RosarioSIS versions prior to 12.9. This vulnerability allows authenticated users to manipulate the filename request parameter in the Users and Students modules, unlinking allow-listed files through directory traversal. By using parent-directory sequences to escape upload directories, attackers can delete various resource types, including CSS, XML, JSON files, and other users' documents across the installation.
Users can upgrade to RosarioSIS version 12.9, which addresses this vulnerability by implementing proper path traversal checks in the file deletion handler.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 17, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/kazisabu/68bd095bc05b2341db318a063e05e644 | CISA-ADP | Technical Description |
| https://gist.github.com/kazisabu/68bd095bc05b2341db318a063e05e644 | [email protected] | Technical Description |
| https://gitlab.com/francoisjacquet/rosariosis | [email protected] | ProductSource CodeVendor |
| https://gitlab.com/francoisjacquet/rosariosis/-/commit/701f9c07330157181362927a40d4f8dcc8094d90 | [email protected] | Source CodeVendor |
| https://www.vulncheck.com/advisories/rosariosis-before-12.9-path-traversal-in-file-deletion-via-filename-parameter | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| RosarioSIS | < 12.9 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | New CVE Received | [email protected] |
| Sep 17, 2026 | CVE Modified | CISA-ADP |
Volerion