Description
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wf5p-f5xr-c4jj | SQL Injection in rosariosis |
References
| Link | Providers |
|---|---|
| https://gitlab.com/francoisjacquet/rosariosis/-/issues/328 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:25:16.300Z
Reserved: 2021-11-29T00:00:00.000Z
Link: CVE-2021-44427
No data.
Status : Modified
Published: 2021-11-29T22:15:07.533
Modified: 2026-06-17T04:12:19.827
Link: CVE-2021-44427
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA