VulnerabilityDeferred
CVE-2026-19784
This manipulation causes authorization bypass.
LOW 2.1EPSS 0.27%
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Discipline/Referrals.php. This manipulation causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 12.9 is able to mitigate this issue. Patch name: 04dd1a368ddf80ad7082baefa3c656e4e1825c76. It is suggested to upgrade the affected component.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285, CWE-639
- Source
- cna@vuldb.com
References
- https://github.com/francoisjacquet/RosarioSIS/commit/04dd1a368ddf80ad7082baefa3c656e4e1825c76
- https://github.com/francoisjacquet/RosarioSIS/issues/301
- https://github.com/francoisjacquet/RosarioSIS/issues/301
- https://github.com/francoisjacquet/rosariosis/
- https://github.com/francoisjacquet/rosariosis/issues/301
- https://github.com/francoisjacquet/rosariosis/issues/301
- https://github.com/francoisjacquet/rosariosis/releases/tag/v12.9
- https://vuldb.com/cve/CVE-2026-19784
- https://vuldb.com/submit/869367
- https://vuldb.com/vuln/389744
- https://vuldb.com/vuln/389744/cti
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.