Junglewise Threat Intelligence

CVE-2026-19785: francoisjacquet RosarioSIS SQL injection in Student Medical Module

CVE-2026-19785 · Severity: medium · CVSS 6.3 · Published 2026-08-14

Technologies: Francoisjacquet RosarioSIS. Vendors: Francoisjacquet.

Executive brief

RosarioSIS is a student information system used by schools for managing student records and operations. An attacker can inject malicious SQL code through the student medical records module, potentially allowing them to read, modify, or delete sensitive student health information and other database records remotely without authentication.

Technical details

A SQL injection vulnerability exists in the Student Medical Module (modules/Students/includes/Medical.inc.php) of RosarioSIS versions up to 12.7.4. The vulnerability is triggered through unsanitized manipulation of the 'table' parameter in HTTP requests, allowing an attacker to execute arbitrary SQL commands against the application database. The attack is network-accessible and does not require authentication. An attacker can query, modify, or delete database records depending on database permissions. The vulnerability was patched in version 12.8 (commit 6234a0ee0124c0667c824693ac77164f18946ddf).

Affected products

  • francoisjacquet RosarioSIS up to 12.7.4

Timeline

  • 2026-08-14: disclosed
  • 2026: patched: Version 12.8 includes the fix

References

Related threats