Rosariosis is a student information system deployed across educational institutions, and its vulnerability footprint centers on web-application input-handling and access-control flaws endemic to that class of platform. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring weakness classes include cross-site scripting, SQL injection, improper access control, and exposure of sensitive information, reflecting the data-intensive and web-facing nature of student record management. Defenders should prioritize patching this vendor's disclosures given the sensitive personal and academic data at stake; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rosariosis over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44427CRITICAL An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., S | Nov 29, 2021 | 9.8 | 69 | NO | YES |
CVE-2021-44567CRITICAL An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php. | Feb 24, 2022 | 9.8 | 54 | NO | YES |
CVE-2020-15718MEDIUM RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability usi | Jul 15, 2020 | 6.1 | 45 | NO | YES |
CVE-2020-15716MEDIUM RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using | Jul 15, 2020 | 6.1 | 32 | NO | YES |
CVE-2022-2714CRITICAL Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0. | Sep 6, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-29918MEDIUM RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module. | May 2, 2023 | 5.4 | 29 | NO | YES |
CVE-2022-2067CRITICAL SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0. | Jun 13, 2022 | 9.1 | 29 | NO | NO |
CVE-2023-2665HIGH Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0. | May 12, 2023 | 7.5 | 25 | NO | NO |
CVE-2023-0994HIGH Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2. | Feb 24, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-45416MEDIUM Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php | Feb 1, 2022 | 6.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rosariosis.
Media articles that mention a CVE ID that affects a product developed by Rosariosis — matched by CVE ID, not by vendor name.