What is CVE-2026-19786?
A CSRF (Cross-Site Request Forgery) vulnerability was found in the Modules.php file of the RosarioSIS school management system. It allows remote attackers to perform unauthorized actions on behalf of authenticated users. Versions up to 12.8 are affected, upgrading to version 12.9 is advised.
Azərbaycanca: RosarioSIS məktəb idarəetmə sistemində Modules.php faylında CSRF (Cross-Site Request Forgery) zəifliyi aşkar edilib. Bu boşluq autentifikasiya olunmuş istifadəçi adından icazəsiz əməliyyatların icrasına imkan verir. 12.8-ə qədər olan versiyaları təsirləndirir, 12.9 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
In which file was the CVE-2026-19786 vulnerability discovered?
This CSRF vulnerability was found in the Modules.php file of the RosarioSIS school management system.
Which version is recommended to upgrade to in order to mitigate CVE-2026-19786?
Versions up to 12.8 are affected, so upgrading to version 12.9 is advised.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.