An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.
{
"cwe_ids": [
"CWE-89"
],
"github_reviewed": true,
"nvd_published_at": "2021-11-29T22:15:00Z",
"severity": "CRITICAL",
"github_reviewed_at": "2021-12-01T21:03:52Z"
}