S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-44427 Scanner

CVE-2021-44427 scanner - SQL Injection vulnerability in Rosario Student Information System (aka rosariosis)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-44427
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Rosario Student Information System (aka rosariosis) is a web-based software that provides educational institutions with an efficient way of managing student information. This open-source platform offers a wide range of functions such as student enrollment, grading, scheduling, report generation, and many more. This system is accessible from any location and can be easily customized to match the needs of any educational institution.

The CVE-2021-44427 vulnerability was recently detected in this product. The vulnerability occurs due to an unauthenticated SQL injection vulnerability which allows remote attackers to execute PostgreSQL statements through /Side.php via the syear parameter. This means that hackers can gain access to sensitive information such as personal student data, grades, and other confidential information.

When this vulnerability is exploited, it can lead to devastating consequences for educational institutions that rely on Rosario Student Information System. Hackers can gain unauthorized access to student information, manipulate grades, and even disrupt the entire educational process, causing chaos and panic amongst students and parents.

In conclusion, with the pro features of the s4e.io platform, educational institutions can quickly and easily learn about vulnerabilities in their digital assets. The platform offers various features such as automated vulnerability scanning, risk assessment, and remediation guidance, which can help educational institutions to secure their digital assets and prevent cyber attacks. With the rising number of cyber attacks on educational institutions, securing digital assets is not just an option but a necessity to protect sensitive information and preserve the educational process.

 

REFERENCES

Solution Advice

To protect against this vulnerability, educational institutions should take the following precautions:

  • Disable or restrict access to Side.php via the web server configuration
  • Enforce strong and complex passwords for all Rosario Student Information System users
  • Ensure that the software is up-to-date with the latest security patches
  • Implement a web application firewall (WAF) to monitor and filter traffic to Rosario Student Information System 
  • Regularly conduct vulnerability assessments and penetration tests to detect and remediate vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-44427 scanner - SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) | S4E