PT-2025-17591 · Unknown · Rosariosis
Published
2025-04-22
·
Updated
2025-04-23
·
CVE-2025-29621
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Francois Jacquet RosarioSIS version 12.0.0
Description
The issue is related to a content spoofing vulnerability found in the Theme configuration under the My Preferences module. This allows attackers to manipulate application settings.
Recommendations
For version 12.0.0, consider restricting access to the Theme configuration under the My Preferences module until a fix is available. As a temporary workaround, limit the ability to manipulate application settings to prevent potential exploitation.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rosariosis