RosarioSIS improper access control vulnerability
Moderate severity
GitHub Reviewed
Published
Apr 21, 2023
to the GitHub Advisory Database
•
Updated Nov 9, 2023
Description
Published by the National Vulnerability Database
Apr 21, 2023
Published to the GitHub Advisory Database
Apr 21, 2023
Reviewed
Apr 24, 2023
Last updated
Nov 9, 2023
RosarioSIS prior to version 10.9.3 has a vulnerability that allows a user to return to a page containing personally identifiable information (PII) and sensitive information even after logging out of the application by using the browser's back button.
References