Vulnerabilities > Rosariosis > High

DATE CVE VULNERABILITY TITLE RISK
2023-05-12 CVE-2023-2665 Insecure Storage of Sensitive Information vulnerability in Rosariosis
Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0.
network
low complexity
rosariosis CWE-922
7.5
2023-02-24 CVE-2023-0994 Information Exposure vulnerability in Rosariosis
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.
network
low complexity
rosariosis CWE-200
7.5
2022-02-24 CVE-2021-44567 SQL Injection vulnerability in Rosariosis
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
network
low complexity
rosariosis CWE-89
7.5
2021-11-29 CVE-2021-44427 SQL Injection vulnerability in Rosariosis
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.
network
low complexity
rosariosis CWE-89
7.5