Sceawere
Vulnerability Detail
CVE-2026-19784UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
RosarioSIS Discipline Referrals Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- francoisjacquet
- Product
- RosarioSIS
- Attack Type
- Authorization Bypass
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Discipline/Referrals.php. This manipulation causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 12.9 is able to mitigate this issue. Patch name: 04dd1a368ddf80ad7082baefa3c656e4e1825c76. It is suggested to upgrade the affected component.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-08-14T03:16:20.373Z",
"pubdate": "2026-08-14T03:16:20.373Z",
"executiveSummary": "An authorization bypass vulnerability has been identified in francoisjacquet RosarioSIS up to version 12.8, specifically within the DBUpdate function located in Discipline/Referrals.php. This security flaw allows remote attackers to bypass intended access controls and manipulate database updates without proper authorization. The vulnerability poses a significant risk to the integrity and confidentiality of student discipline records within the affected school administration systems. Exploitation of this flaw can be initiated remotely by an unauthorized or unprivileged actor over the network, provided they have access to the target application endpoint. The public availability of exploit details increases the likelihood of active exploitation in the wild. Organizations utilizing vulnerable deployments of RosarioSIS face potential unauthorized data modification and privilege escalation risks within the student information system. Mitigating this exposure requires immediate administrative action to apply vendor-supplied patches and secure the application against remote manipulation vectors.",
"technicalDetails": "The vulnerability resides in the Discipline/Referrals.php script of francoisjacquet RosarioSIS up to version 12.8, specifically within the DBUpdate function responsible for processing database transactions related to student discipline referrals. The root cause of the flaw stems from insufficient or absent authorization checks prior to executing critical database update operations. In a secure architecture, functions handling state-changing requests must rigorously validate the session context, user roles, and access control lists (ACLs) to ensure the initiator possesses the requisite administrative privileges. However, in the affected versions, the DBUpdate function fails to properly verify whether the incoming request originates from an authorized user with appropriate permissions to modify discipline records.\nThe attack flow begins with a remote network adversary targeting the vulnerable Discipline/Referrals.php endpoint. Because the application fails to enforce strict access controls on the vulnerable function, an attacker can craft a malicious HTTP request directed at the application. By directly invoking or manipulating the parameters passed to the DBUpdate function, the attacker bypasses the logical authorization barriers enforced elsewhere in the application architecture. The lack of robust input validation and session authorization allows the crafted payload to be processed directly by the backend database interaction routines.\nNetwork exposure is inherent to web-based deployments of RosarioSIS, making the endpoint accessible to remote actors over standard HTTP/HTTPS protocols. Depending on the exact network configuration and deployment posture, authentication requirements may be entirely circumvented or bypassed due to the flaw in the function's logic, permitting unauthenticated or low-privileged remote attackers to execute high-privilege administrative actions. The post-exploitation impact includes unauthorized modification, insertion, or deletion of sensitive discipline referral records, leading to severe data tampering, integrity compromise, and potential compliance violations regarding student data privacy."
}