Unknown · Rosariosis · CVE-2023-2202
**Name of the Vulnerable Software and Affected Versions**
RosarioSIS versions prior to 10.9.3
**Description**
The issue allows a user to access a page containing personally identifiable information (PII) and sensitive information after logging out of the application by using the browser's back button. This is due to improper access control.
**Recommendations**
For versions prior to 10.9.3, update to version 10.9.3 or later to resolve the issue. As a temporary workaround, consider clearing browser history and cache after logging out to minimize the risk of exploitation. Restrict access to sensitive pages to minimize the risk of unauthorized access.